Junglewise Threat Intelligence

CVE-2026-14837: Lenze Multiple Products improper signature verification in SSH enablement

CVE-2026-14837 · Severity: high · CVSS 7.8 · Published 2026-07-27

Executive brief

Multiple Lenze industrial controllers and servo drives contain a security flaw in how they verify authorization files used to enable remote maintenance access (SSH). An attacker with local access to the device, such as through an SD card or low-level user account, can bypass these security checks to gain full administrative control. This could allow an attacker to disrupt industrial operations, steal sensitive configuration data, or modify the device's behavior.

Technical details

An improper verification of cryptographic signature (CWE-347) exists in the SSH enablement routine of several Lenze industrial products. The vulnerability allows a local attacker with low privileges to bypass the signature check on a specific activation file (often placed on an SD card) used to enable the SSH service. By successfully bypassing this verification, the attacker can activate SSH access and subsequently gain unauthorized administrative shell access to the underlying operating system. The attack requires local access to the device's file system or physical access to the SD card slot. Patches have been released for the affected controller and servo drive firmware versions.

Affected products

  • Lenze c430 < 1.15.2
  • Lenze c520 < 1.15.2
  • Lenze c550 < 1.15.2
  • Lenze i950 GenA < 1.14.2
  • Lenze i950 GenB < 2.0.3

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory

References