CVE-2026-11841: CWE-552 Files or directories accessible to external parties in SICK AG InspectorP61x
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.
AI Analysis
Technical Summary
The vulnerability arises from improper access restrictions in the AppEngine Fileaccess over HTTP feature of InspectorP61x, which unintentionally exposes critical filesystem directories without requiring authentication. Attackers can access device parameter files to read or alter application settings, including customer-defined passwords. Furthermore, exposure of the custom application directory enables execution of arbitrary Lua code within the sandboxed AppEngine environment, increasing the risk of unauthorized control or manipulation of the device.
Potential Impact
Successful exploitation allows unauthenticated attackers to read and modify sensitive device parameters, including passwords, compromising confidentiality and integrity. Additionally, arbitrary Lua code execution within the sandboxed environment can lead to further unauthorized actions, potentially impacting device availability. The CVSS score of 9.4 reflects the high severity and ease of exploitation over the network without privileges or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround has been documented at this time. Until a patch is available, restrict network access to the affected device's HTTP file access feature to trusted users only, and monitor for any unusual activity related to file access.
CVE-2026-11841: CWE-552 Files or directories accessible to external parties in SICK AG InspectorP61x
Description
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.
CVSS v3.1
Score 9.4critical
Affected software
SICK AG
InspectorP61x
SICK AG
InspectorP62x
SICK AG
InspectorP65x
SICK AG
InspectorP63x
SICK AG
InspectorP64x
SICK AG
ICR890-4
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from improper access restrictions in the AppEngine Fileaccess over HTTP feature of InspectorP61x, which unintentionally exposes critical filesystem directories without requiring authentication. Attackers can access device parameter files to read or alter application settings, including customer-defined passwords. Furthermore, exposure of the custom application directory enables execution of arbitrary Lua code within the sandboxed AppEngine environment, increasing the risk of unauthorized control or manipulation of the device.
Potential Impact
Successful exploitation allows unauthenticated attackers to read and modify sensitive device parameters, including passwords, compromising confidentiality and integrity. Additionally, arbitrary Lua code execution within the sandboxed environment can lead to further unauthorized actions, potentially impacting device availability. The CVSS score of 9.4 reflects the high severity and ease of exploitation over the network without privileges or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround has been documented at this time. Until a patch is available, restrict network access to the affected device's HTTP file access feature to trusted users only, and monitor for any unusual activity related to file access.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- SICK AG
- Date Reserved
- 2026-06-10T06:53:18.277Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a6883039c2644c7f8720e39
Added to database: 07/28/2026, 10:22:59 UTC
Last enriched: 07/29/2026, 17:56:15 UTC
Last updated: 09/12/2026, 10:01:29 UTC
Views: 105
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.