Junglewise Threat Intelligence

CVE-2026-3356: Anritsu Remote Spectrum Monitor missing authentication in management interface

CVE-2026-3356 · Severity: info · CVSS 9.8 · Published 2026-03-31

Executive brief

Anritsu Remote Spectrum Monitors, which are used to monitor radio frequency signals in sectors like defense and telecommunications, lack any authentication mechanism for their management interface. This design flaw allows any user with network access to the device to take full control of it. An attacker could change operational settings, intercept sensitive signal data, or cause a complete service outage.

Technical details

The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function). The affected Anritsu Remote Spectrum Monitor models (MS27100A, MS27101A, MS27102A, and MS27103A) do not provide a mechanism to enable or configure authentication for the management interface. This is an inherent design flaw rather than a configuration error. A remote, unauthenticated attacker with network access to the device can access the management interface to alter operational parameters, view sensitive signal data, or disrupt availability. There are currently no plans from the vendor to release a patch; mitigation relies on network isolation and the use of VPNs.

Affected products

  • Anritsu Remote Spectrum Monitor MS27100A All versions
  • Anritsu Remote Spectrum Monitor MS27101A All versions
  • Anritsu Remote Spectrum Monitor MS27102A All versions
  • Anritsu Remote Spectrum Monitor MS27103A All versions

Timeline

  • 2026-03-31: disclosed: Initial disclosure by CISA and ICS-CERT
  • 2026-03-31: advisory: ICSA-26-090-01 published

References