Red Lion N-Tron 700 Series industrial switches: seven flaws (CISA ICSA-26-281-01, CVSS up to 8.1) let attackers use unauthenticated SNMP to pull configs, change accounts and push firmware, read plaintext and weakly encrypted passwords, and reboot-loop the switch; fix is firmware 3.11.1
CISA published ICS advisory ICSA-26-281-01 on 8 October 2026 for Red Lion Controls N-Tron 700 Series managed Ethernet switches (Red Lion is part of Sweden's HMS Networks), used worldwide in critical manufacturing, communications and commercial facilities. Firmware 3.11.0 and earlier and bootloader 2.0.6.1 and earlier are affected by seven CVEs: SNMP can retrieve configuration files, change user accounts and settings and start firmware or bootloader upgrades or downgrades without authentication (CVE-2026-33367, CVSS 3.1 8.1); usernames and passwords, including factory defaults, sit in plaintext in the configuration file and can be exported by TFTP, which SNMP can trigger without logging in (CVE-2026-39460, 8.1); browsing to a particular URL on the web server reboots the switch, which can be scripted for a constant reboot loop (CVE-2026-39453, 8.3); credentials are stored with weak, recoverable encryption (CVE-2026-28745, 7.5); firmware and bootloader updates need no authentication and N-Tron devices can be found and pushed new firmware over SNMP/TFTP (CVE-2026-29797, 7.1); factory administrator credentials stay active even after other admin accounts are set up (CVE-2026-32645, 6.0); and someone with physical access can boot to factory settings and log in with the defaults (CVE-2026-33272, 4.9). CISA lists no known public exploitation. Primary: CISA advisory (CSAF); vendor: HMS Networks cybersecurity page.
- Product
- Red Lion Controls N-Tron 700 Series managed industrial Ethernet switches
- Versions
- Firmware 3.11.0 and earlier; bootloader 2.0.6.1 and earlier
- CVSS
- (CVSS 3.1, highest: CVE-2026-39453); 8.1 for CVE-2026-33367 and CVE-2026-39460
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H (CVE-2026-39453) - Exploited in Australia?
- unknown
- Patch to
- Upgrade N-Tron 700 Series firmware to 3.11.1 or later using Red Lion's upgrade procedure. Until then, configure or disable SNMP communities, disable the web GUI where it is not needed, change factory admin credentials, and keep the switches off business networks and the internet behind firewalls.
Primary: CISA ICS advisory ICSA-26-281-01 — Red Lion Controls N-Tron 700 Series (8 Oct 2026) · Vendor: HMS Networks (Red Lion) — cybersecurity advisories · CVE: CVE-2026-33367, CVE-2026-39460, CVE-2026-39453, CVE-2026-28745, CVE-2026-29797, CVE-2026-32645, CVE-2026-33272 · CISA CSAF — icsa-26-281-01.json
