Junglewise Threat Intelligence

CVE-2026-22920: SICK TDC-x401GL inadequate password salting

CVE-2026-22920 · Severity: info · CVSS 7.5 · Published 2026-01-15

Executive brief

SICK TDC-x401GL gateway devices were found to use inadequate security measures for protecting stored passwords. This flaw could allow an attacker to more easily crack and extract user passwords if they gain access to the device's data. While the specific CVE identifier was later rejected by the authority, the underlying issue involves how the device secures credentials.

Technical details

The SICK TDC-x401GL firmware fails to use adequate salting mechanisms when hashing passwords (CWE-1391). This vulnerability allows an attacker with access to the password hashes to perform more efficient offline brute-force or rainbow table attacks to recover plaintext credentials. Although the CVE was marked as 'Rejected' by the CNA (SICK AG) in May 2026, the initial disclosure indicated a network-based attack vector. Security engineers should verify if the rejection was due to a duplicate entry or a fix being integrated into standard operating guidelines.

Affected products

  • SICK AG TDC-x401GL firmware All versions prior to rejection

Timeline

  • 2026-01-15: disclosed: Initial disclosure by SICK AG
  • 2026-05-12: other: CVE rejected/withdrawn by SICK AG