CVE-2026-25086
Automated Logic WebCTRL Premium Server Multiple Binds to the Same Port
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.7EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Under certain conditions, an attacker could bind to the same port used
by WebCTRL. This could allow the attacker to craft and send malicious
packets and impersonate the WebCTRL service without requiring code
injection into the WebCTRL software.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Automated Logic · WebCTRL Premium ServerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →