Junglewise Threat Intelligence

CVE-2026-11849: IEI iRM-IEI Remote Management hardcoded credentials in database

CVE-2026-11849 · Severity: critical · CVSS 9.8 · Published 2026-06-12

Vendors: IEI Integration Corp.

Executive brief

IEI iRM-IEI Remote Management is a tool used for the remote monitoring and management of industrial computing hardware. A vulnerability exists where hardcoded login credentials allow an unauthorized person to gain full administrative control over the system's database. This could lead to the theft of sensitive configuration data, unauthorized modification of system settings, or a complete loss of control over the managed hardware.

Technical details

A hardcoded credentials vulnerability (CWE-798) exists in the iRM-IEI Remote Management software used in IEI iRM-TSi410X devices. The flaw allows an unauthenticated attacker with network access to the management interface to use static, pre-defined credentials to authenticate to the underlying database. Successful exploitation grants the attacker administrative privileges, enabling full access to read, modify, or delete database records. This vulnerability is addressed in version v1.4.19.

Affected products

  • IEI Integration Corp iRM-TSi410X before v1.4.19

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory
  • 2026-06-12: patched: Fixed in version v1.4.19

References

Related threats