Red Lion N-Tron 700: seven flaws, upgrade to firmware 3.11.1
CISA ICSA-26-281-01 hardcoded credentials and unauthenticated SNMP

Red Lion N-Tron 700: seven flaws, upgrade to firmware 3.11.1

CISA published ICS advisory ICSA-26-281-01 on 8 October 2026 for Red Lion Controls N-Tron 700 Series switches. Seven vulnerabilities can give an attacker administrative access, configuration export, or a scripted reboot loop. Firmware 3.11.0 and earlier, and bootloader 2.0.6.1 and earlier, are affected.

What happened

The switch family is used in commercial facilities, communications, critical manufacturing, and IT, and is deployed worldwide. CISA's highest listed CVSS v3 score on the set is 8.3. No known public exploitation has been reported to CISA. The vendor fix is firmware 3.11.1 or greater. HMS Networks issued a matching vendor advisory.

The practical holes are old industrial habits. CVE-2026-32645 is factory admin credentials that stay active after you create other administrator accounts. CVE-2026-39460 stores usernames and passwords, including those defaults, in plaintext in the configuration file. That file can be exported by TFTP, and a TFTP transfer can be started over SNMP without authentication. CVE-2026-33367 lets SNMP change accounts, pull configs, and start firmware upgrades with no authentication.

Who is affected

Sites running N-Tron 700 Series at firmware 3.11.0 or below, or bootloader 2.0.6.1 or below. That includes plant networks where the switch management IP is reachable from a wider OT or IT VLAN, and anywhere SNMP communities were left at defaults. A reboot loop on a switch in a packaging line or a camera VLAN is an availability incident, not just a config leak.

What to do now

Inventory N-Tron 700 switches, upgrade to firmware 3.11.1 or greater, and disable or reconfigure SNMP communities before the management IP is reachable from outside the cell. Turn off the web GUI if you do not need it. After the upgrade, change every admin password. Factory credentials that persist are not fixed by adding a second account. Segment switch management from the enterprise LAN.

Source: CISA ICS advisory ICSA-26-281-01, 8 October 2026, Red Lion Controls N-Tron 700 Series.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Cisco NX-OS CVE-2026-76471 scores 9.8 on Nexus 3000 and 9000
Unauthenticated root code execution via NX-API