Executive brief
The Aclara Metrum Cellular Web Interface, used in energy infrastructure, contains a security flaw where critical system functions do not require a password. An unauthorized person could remotely access the device to change configuration settings or force the system to restart. This could lead to service disruptions or a total loss of communication with the device, potentially impacting utility operations.
Technical details
The Aclara Metrum Cellular Web Interface suffers from a missing authentication vulnerability (CWE-306) for critical system functions. An unauthenticated remote attacker can access the web interface to modify operational parameters and trigger system restarts. The root cause is the lack of authentication enforcement on sensitive configuration endpoints. Successful exploitation allows for persistent denial-of-service by repeatedly disrupting device operations or causing a complete loss of communication. Hubbell has released firmware version 2.1.0.105 to address this issue.
Affected products
- Hubbell Aclara Metrum Cellular Web Interface < 2.1.0.105
Timeline
- 2026-06-23: advisory: Initial CISA ICS Advisory (ICSA-26-174-07) released.
- 2026-06-24: disclosed: CVE-2026-1840 published to NVD.