Executive brief
X-Rite MA-T6 spectrophotometers, which are precision instruments used for measuring color and appearance in manufacturing and design, contain a critical security flaw. An attacker can remotely take control of the device without needing a password or physical access. This could allow an unauthorized user to disrupt operations, alter measurement data, or use the device as a foothold to access other parts of the corporate network.
Technical details
X-Rite MA-T6 spectrophotometers running firmware versions prior to v2.33 are vulnerable to an origin validation error (CWE-346). The device fails to correctly verify the source of incoming communication requests on certain channels, allowing an unauthenticated attacker to send malicious commands over the network. Successful exploitation grants the attacker remote command execution (RCE) capabilities with high impact on confidentiality, integrity, and availability. The vulnerability is addressed in firmware version v2.33.
Affected products
- X-Rite MA-T6 Spectrophotometer before v2.33
Timeline
- 2026-07-16: advisory: NVD and CERT VDE published the vulnerability details.
- 2026-07-16: disclosed: Claroty Team82 disclosed the vulnerability details.