Junglewise Threat Intelligence

CVE-2026-3893: Carlson VASCO-B GNSS Receiver missing authentication

CVE-2026-3893 · Severity: critical · CVSS 9.4 · Published 2026-04-28

Executive brief

The Carlson VASCO-B GNSS Receiver, a device used for high-precision satellite positioning and navigation, contains a critical security flaw where it lacks any authentication requirements. This allows an unauthorized person with network access to the device to change its settings or disrupt its operations. Such an exploit could lead to inaccurate positioning data, service outages, or complete loss of control over the hardware.

Technical details

The Carlson VASCO-B GNSS Receiver is vulnerable to CWE-306 (Missing Authentication for Critical Function). The device fails to implement any credential-based access control for its management interface or operational functions. An unauthenticated attacker with network reachability can remotely access the device to modify system configurations, alter operational parameters, or cause a denial-of-service condition. The vulnerability was reported by ICS-CERT with a CVSS v3.1 base score of 9.4. Users are advised to contact the vendor for support and potential firmware updates.

Affected products

  • Carlson VASCO-B GNSS Receiver

Timeline

  • 2026-04-28: advisory: Initial disclosure by ICS-CERT/NVD

References