CVE-2026-4436
8.6GPL Odorizers · GPL750 (XL4, XL4 Prime, XL7, XL7 Prime)
A remote, low-privileged attacker can manipulate Modbus registers in GPL750 odorizers to disrupt natural gas odorant injection levels.
Executive summary
A critical vulnerability in GPL Odorizers GPL750 devices allows remote attackers to compromise industrial gas odorization processes, posing significant safety and operational risks.
Vulnerability
The vulnerability, categorized as CWE-306 (Missing Authentication for Critical Function), allows an unauthenticated remote attacker to send malicious Modbus packets to the device. This enables unauthorized modification of registers controlling odorant injection logic.
Business impact
The ability to manipulate odorant injection levels in gas lines poses a severe risk to public safety and physical infrastructure. Because odorization is a critical safety requirement for detecting gas leaks, failure to maintain correct levels can result in catastrophic incidents. With a CVSS score of 8.6, this flaw represents a High severity risk that could lead to widespread operational disruption and significant liability.
Remediation
Immediate Action: Update the GPL750 firmware to version 6.0 or 20.0 (depending on the model) by following the vendor provided instructions to extract updated files to a microSD card or obtaining a preconfigured card from the manufacturer.
Proactive Monitoring: Monitor network traffic for unauthorized Modbus communications targeting the affected GPL750 devices and review system logs for unexpected register changes.
Compensating Controls: Implement strict network segmentation to isolate industrial control systems from external networks and deploy industrial firewalls capable of deep packet inspection to block unauthorized Modbus commands.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the safety-critical nature of the affected equipment, administrators must prioritize this update across all deployment sites. Ensure that all firmware update procedures are performed according to the specific vendor instructions provided in the CISA advisory to prevent further operational instability.
Sources
Originally found and disclosed by An anonymous researcher reported this vulnerability to CISA., per the CVE Program record.