CVE-2026-25086

7.7

Automated Logic · WebCTRL

A vulnerability in Automated Logic WebCTRL allows an attacker to bind to the same network port as the service, facilitating the impersonation of the WebCTRL service through malicious packet injection.

Executive summary

A high-severity vulnerability in Automated Logic WebCTRL allows unauthenticated attackers to impersonate the service by binding to its network port, potentially leading to unauthorized system control.

Vulnerability

This flaw, categorized as CWE-605 (Multiple Bindings to the Same Port), allows an unauthenticated attacker to intercept or spoof communications by binding to the port used by WebCTRL, enabling the impersonation of the service without requiring code injection.

Business impact

The ability for an attacker to impersonate the WebCTRL service poses a significant risk to industrial and building control environments. A successful exploit could result in the unauthorized manipulation of operational technology, leading to process disruption, system downtime, or the compromise of sensitive building management data. With a CVSS score of 7.7, this vulnerability represents a high risk to operational continuity and system integrity.

Remediation

Immediate Action: Upgrade all instances of the WebCTRL server application to version 8.5 or later, which provides support for the secure BACnet/SC protocol.

Proactive Monitoring: Monitor network traffic for unexpected packet patterns or unauthorized attempts to bind to known service ports, and regularly review system access logs for anomalies.

Compensating Controls: Implement strict network segmentation to isolate the WebCTRL server from untrusted networks and utilize access control lists to restrict traffic to authorized communication channels.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of this vulnerability and its potential impact on critical infrastructure, administrators should prioritize the upgrade to WebCTRL 8.5 immediately. Where immediate patching is not feasible, network-level isolation and the enforcement of secure configurations are essential to mitigate the risk of service impersonation.

More Automated Logic CVEs

Sources

Originally found and disclosed by Jonathan Lee, Thuy D. Nguyen, and Neil C. Rowe of the Naval Postgraduate School reported this vulnerability to CISA., per the CVE Program record.