Junglewise Threat Intelligence

CVE-2026-0647: Rockwell Automation 1794-AENTR improper authentication in web server

CVE-2026-0647 · Severity: info · CVSS 9.4 · Published 2026-06-16

Vendors: Rockwell Automation.

Executive brief

A security vulnerability exists in Rockwell Automation FLEX I/O adapters, which are used to connect industrial equipment to automation networks. An attacker can remotely change the device's web management password without needing any existing credentials. This could allow an unauthorized user to take full control of the device's web interface, potentially disrupting industrial operations or modifying device configurations.

Technical details

An improper authentication vulnerability (CWE-306) exists within the embedded web server of Rockwell Automation 1794-AENTR and 1794-AENTRXT FLEX I/O adapters. The flaw allows a remote, unauthenticated attacker to reset or change the web interface password by sending a specifically crafted HTTP GET request to a vulnerable endpoint. Successful exploitation results in complete account takeover of the web management interface and potential loss of availability of the web server. The issue is fixed in firmware version 2.013.

Affected products

  • Rockwell Automation 1794-AENTR / 1794-AENTRXT FLEX I/O EtherNet/IP Adapters 2.012

Timeline

  • 2026-05-20: other: Initial internal revision date
  • 2026-06-16: advisory: Public advisory released by Rockwell Automation
  • 2026-06-16: patched: Firmware version 2.013 released to address the issue

References

Related threats