Junglewise Threat Intelligence

CVE-2026-9141: Taiko AG1000-01A SMS Alert Gateway authentication bypass in web interface

CVE-2026-9141 · Severity: critical · CVSS 9.8 · Published 2026-05-20

Technologies: Taiko AG1000-01A SMS Alert Gateway. Vendors: Taiko.

Executive brief

The Taiko AG1000-01A SMS Alert Gateway, a device used to send critical SMS notifications for industrial and monitoring systems, contains a flaw in its web management interface. This vulnerability allows an unauthorized person to bypass security checks and gain full administrative control over the device. An attacker could change how alarms are routed, modify device settings, or disable monitoring entirely, potentially leading to missed emergency alerts or operational downtime.

Technical details

The Taiko AG1000-01A SMS Alert Gateway (Rev 7.3 and 8) suffers from a missing authentication check (CWE-306) within its embedded web server. The application fails to implement session management or server-side validation for critical configuration pages. A remote, unauthenticated attacker can gain full administrative read and write access by directly requesting internal resources such as index.zhtml, point.zhtml, and log.shtml. This allows for the unauthorized modification of alarm routing and device configurations. No user interaction or prior credentials are required for exploitation.

Affected products

  • Taiko AG1000-01A SMS Alert Gateway Rev 7.3, Rev 8, UM-AG1000_R7.2

Timeline

  • 2026-05-20: advisory: NVD and VulnCheck published the vulnerability details.
  • 2026-05-20: disclosed

References

Related threats