CVE-2026-94293: AAS Edge Client flaw rated 9.8, no patch
Murrelektronik's AAS Edge Client contains CVE-2026-94293 (CVSS 9.8): an unauthenticated REST API on TCP port 18000 bound to all interfaces. Any network-reachable attacker can read AAS submodel data via GET and overwrite it via PATCH, with changes propagating to central AAS servers. No patch exists; the vendor archived the repositories and recommends decommissioning.
- CVSS 9.8: unauthenticated REST API on TCP port 18000
- GET reads and PATCH overwrites AAS submodel data
- Unrestricted CORS enables browser-based attacks
- No patch; vendor advises decommissioning the product
Read next
Security