Executive brief
A vulnerability exists in X-Rite MA-T6 spectrophotometers, which are precision instruments used for measuring color and appearance in manufacturing and design. An attacker can remotely take complete control of the device without needing a password. This could lead to the theft of proprietary measurement data, disruption of quality control processes, or the use of the device as a foothold to attack other parts of the corporate network.
Technical details
The vulnerability is classified as an OS Command Injection (CWE-78) within the 'SetParameter' command of the X-Rite MA-T6 Kohinoor firmware. The root cause is the failure to correctly sanitize user-supplied input before it is processed by the system, allowing an attacker to inject malicious commands. This attack can be carried out over the network without any prior authentication or user interaction. Successful exploitation grants the attacker remote code execution (RCE) with the privileges of the affected process. The issue is addressed in firmware version v2.33.
Affected products
- X-Rite MA-T6 firmware before v2.33
Timeline
- 2026-07-16: advisory: NVD and CERT VDE published the vulnerability details.