Junglewise Threat Intelligence

CVE-2026-27868: Teldat Regesta Smart HD-PLC information disclosure in query.php

CVE-2026-27868 · Severity: info · CVSS 6.9 · Published 2026-06-17

Technologies: Teldat Regesta Smart HD-PLC - TLDPH16D2. Vendors: Teldat.

Executive brief

A vulnerability in Teldat's Regesta Smart industrial routers allows unauthorized individuals to access sensitive system information over the network. By sending a specific command to the device's web interface, an attacker can view version details and other privileged data without needing to log in. This could allow an attacker to better plan further attacks or gain insights into the organization's industrial infrastructure.

Technical details

An information disclosure vulnerability exists in the Teldat Regesta Smart HD-PLC (TLDPH16D2) industrial router. The flaw is located in the '/upgrade/query.php' component, which fails to properly restrict access to sensitive system commands. A remote, unauthenticated attacker can exploit this by sending a crafted HTTP request using the 'Version' command (e.g., '/upgrade/query.php?cmd=p+3&3Bversion'). Successful exploitation allows the attacker to obtain privileged system information, categorized under CWE-201 (Insertion of Sensitive Information Into Sent Data). The vendor has released firmware version 11.02.06.00.02 to address this issue.

Affected products

  • Teldat Regesta Smart HD-PLC - TLDPH16D2 11.02.05.10.02

Timeline

  • 2026-06-17: advisory: Initial disclosure by HackRTU CNA
  • 2026-06-17: patched: Firmware version 11.02.06.00.02 released to address the issue

References

Related threats