Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.

Project Subscriptions

Vendors Products
C4xx Firmware Subscribe
C5xx Firmware Subscribe
I950 Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 27 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
Title SSH Enablement Signature Verification Bypass
First Time appeared Lenze
Lenze c4xx Firmware
Lenze c5xx Firmware
Lenze i950 Firmware
Weaknesses CWE-347
CPEs cpe:2.3:o:lenze:c4xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:lenze:c5xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:lenze:i950_firmware:*:*:*:*:*:*:*:*
Vendors & Products Lenze
Lenze c4xx Firmware
Lenze c5xx Firmware
Lenze i950 Firmware
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-27T07:03:27.889Z

Reserved: 2026-07-06T09:59:37.390Z

Link: CVE-2026-14837

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses