CVE-2026-26341

EUVD-2026-8551
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
tattilesmart\+_firmware
𝑥
≤ 1.181.5
tattiletolling\+_firmware
𝑥
≤ 1.181.5
tattilesmart\+_speed_firmware
𝑥
≤ 1.181.5
tattilesmart\+_traffic_light_firmware
𝑥
≤ 1.181.5
tattileaxle_counter_firmware
𝑥
≤ 1.181.5
tattilevega53_firmware
𝑥
≤ 1.181.5
tattilevega33_firmware
𝑥
≤ 1.181.5
tattilevega11_firmware
𝑥
≤ 1.181.5
tattilebasic_mk2_firmware
𝑥
≤ 1.181.5
tattileanpr_mobile_firmware
𝑥
≤ 1.181.5
𝑥
= Vulnerable software versions