CISA lists four CVEs in every version of Monta's EV-charging platform that let attackers pose as charging stations. Monta is phasing out unauthenticated access on a rolling basis and has not said when it will finish.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence60
Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.
Perspective Coverage
3 publishers
- Builder
- Builder 12%
- Operator
- Operator 76%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence60
Siemens has released V2.70 for the Reyrolle 7SR5 protection relay. The CISA advisory behind it describes a session identifier an unauthenticated remote attacker can derive, plus five memory bugs in an embedded third-party web server.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives45
- Confidence72
CISA says mySCADA myPRO Manager 2.1 and earlier does not enforce authentication on its command API or on the notification gateway that sends SMS through a connected GSM modem. Version 2.2 fixes both.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence68
CISA published seven CVEs against a single CareCam firmware build, one of them a privileged account that accepts an empty password. Its remediation section points users to a vendor that has not answered CISA.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives22
- Confidence66
Every version of five Digital Watchdog VMAX recorder lines ships with a web path that returns administrator passwords in the clear. CISA says the same devices can be used to pivot onto the network behind them.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives25
- Confidence70
ST Engineering's iQ200 answers /api/identity for anyone with network access, handing back the serial number, Device ID and Terminal Private Key identifier that CISA says the platform authenticates with. The fix is 4.5.3.0.
Reality
- Evidence72
- Adoption30
- Hype gap−18
- Incentives20
- Confidence68
Cua's auth check keyed on a container variable while its bind default listened everywhere, and the pair scored 9.8. AutoAgent's blunter version had no fixed release when the records went out.
Reality
- Evidence62
- Adoption32
- Hype gap+8
- Incentives35
- Confidence55
CISA's advisory on the Tycon TPDIN-Monitor-WEB2 covers two flaws below firmware 2.4.5, and the first needs no exploit at all, only a unit whose installer never set the password the vendor expected.
Reality
- Evidence68
- Adoption20
- Hype gap+5
- Incentives32
- Confidence64
CVE-2026-12663 covers every ControlFLASH build through V15.07, where any local account on an engineering workstation could stage code that runs with the privileges of the next engineer to open the firmware updater.
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap−8
- Incentives34
- Confidence70
CVE-2026-75925 lets anything that reaches the client's local configuration interface plant directives in a file a privileged subprocess later runs. Since 5 August 2026 IXON's cloud has refused clients below 1.4.7, which is what actually breaks the chain.
Reality
- Evidence68
- Adoption40
- Hype gap−10
- Incentives58
- Confidence62
PaperCut says the advisory covers all releases of NG and MF, that exploitation is already happening in customer environments, and that its fix is an emergency patch built outside the normal release process.
Reality
- Evidence62
- Adoption45
- Hype gap+12
- Incentives70
- Confidence55
CISA's March 31 advisory assigns CVE-2026-3356 to all versions of four Anritsu Remote Spectrum Monitor models whose management interface has no authentication to switch on. The vendor has no plans to fix it.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap−12
- Incentives30
- Confidence62
CISA's August 27 advisory lists three flaws in the LK100W below firmware 2.1.240, and one of them hands an attacker the authenticated position another one requires. The firmware is the only device-specific fix.
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap+12
- Incentives22
- Confidence70
An unauthenticated attacker reaches administrative functions on the Ebyte gateway's web management interface, and with the vendor silent, the response asset owners still control is where the device sits.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+8
- Incentives30
- Confidence60
A CISA advisory says SIMATIC IoT2050 Advanced units below firmware V4.3.4.1 let an unauthenticated request reach Node-RED programming nodes and run code at maximum privileges.
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap−8
- Incentives45
- Confidence70
CISA says Ebyte confirmed the bug reports and said a fix was in development, then went quiet. Owners of the NE2-D11 gateway now have to plan around firmware that may never be replaced.
Reality
- Evidence76
- Adoption28
- Hype gap−6
- Incentives22
- Confidence68