Junglewise Threat Intelligence

CVE-2026-5416: TURCK Managed Ethernet Switch command injection in name parameter

CVE-2026-5416 · Severity: high · CVSS 8.8 · Published 2026-06-16

Executive brief

A vulnerability exists in TURCK Managed Ethernet Switches, which are used to connect and manage industrial network devices. An attacker with low-level access to the device can take complete control of the switch by injecting malicious commands through a specific naming parameter. This could lead to a total loss of network availability, unauthorized access to industrial data, or a foothold for further attacks on the corporate or production network.

Technical details

A command injection vulnerability (CWE-78) exists in the firmware of TURCK TBEN-Lx-SE-M2 Managed Ethernet Switches. The flaw is rooted in the improper neutralization of special elements within a 'name' parameter, allowing an attacker to execute arbitrary OS commands. Exploitation requires network reachability and low-privileged authentication. Successful exploitation results in full system compromise, impacting confidentiality, integrity, and availability. The vulnerability is addressed in firmware version 2.1.2.0.

Affected products

  • TURCK TBEN-L4-SE-M2 Firmware < 2.1.2.0
  • TURCK TBEN-L5-SE-M2 Firmware < 2.1.2.0
  • TURCK TBEN-LL-SE-M2 Firmware < 2.1.2.0

Timeline

  • 2026-05-19: advisory: Initial advisory released by CERT@VDE and TURCK
  • 2026-06-16: disclosed: CVE published to NVD dataset

References