Junglewise Threat Intelligence

CVE-2026-8173: Murrelektronik Xelity information disclosure in error logging

CVE-2026-8173 · Severity: medium · CVSS 5.3 · Published 2026-08-24

Executive brief

Murrelektronik Xelity switches are network devices used to connect industrial equipment and manage network traffic. When an administrator uses the 'Copy learned MAC Addresses' function, the switch logs device MAC addresses in a web-accessible error message. An attacker without authentication can view these logged MAC addresses through browser developer tools, potentially exposing the network topology and enabling MAC spoofing attacks.

Technical details

The vulnerability is an information disclosure issue (CWE-209: Generation of Error Message Containing Sensitive Information) in the web GUI of Murrelektronik Xelity switches. When an authenticated administrator invokes the 'Copy learned MAC Addresses' function, the device generates a syslog error that exposes the MAC address table to unauthenticated users. The vulnerable code was introduced in firmware version 2.1.0 and affects multiple Xelity switch models. An unauthenticated attacker with network access to the web interface (TCP 80/443) can retrieve the logged MAC addresses via browser developer tools without any further authentication or user interaction. Exploitation enables reconnaissance of OT network topology, potential 802.1X/port-security bypass via MAC spoofing, and correlation of network assets to physical locations. Firmware version 2.1.1 or later resolves the issue.

Affected products

  • Murrelektronik Xelity 2.1.0

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: firmware version 2.1.1 or later

References