CVE-2026-100886 is a critical improper authentication flaw in the Debug Service of several Seetong T-series devices; it can be exploited remotely without credentials, and a public exploit is available.
What Is It
CVE-2026-100886 is an improper authentication vulnerability (CWE-287) in an unspecified function of the Debug Service component on Seetong T8108, T8108P, T8116, and T8232 devices. VulDB is the assigning CNA. The record was published to NVD on 2026-09-27 and currently has "Received" status, which means NVD has not yet analyzed it.
The CNA's CVSS v3.1 score is 10.0 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The CVSS v4.0 score is 9.3 (CRITICAL), and the CVSS v2 score is 10.0.
Why It Matters
- Remote and unauthenticated: The attack works over the network with low complexity. It needs no privileges and no user interaction.
- Full impact: Confidentiality, integrity, and availability are all rated High. The v3.1 scope is Changed, so impact can reach beyond the vulnerable component.
- Public exploit: The NVD description says "the exploit is publicly available and might be used." The CVSS v4.0 exploit maturity is Proof-of-Concept. The public GitHub reference is named
seetong-ts81xxd3x-rce. - No vendor response: VulDB reports that it contacted the vendor early about the disclosure and received no response.
As of 2026-09-27, the CISA Known Exploited Vulnerabilities (KEV) catalog has no entry for this CVE, so KEV does not currently confirm active exploitation.
What's Vulnerable
These Seetong products are affected, all at firmware version 4.6.1.4-build202604241011:
| Product | Affected Module |
|---|---|
| T8108 | Debug Service |
| T8108P | Debug Service |
| T8116 | Debug Service |
| T8232 | Debug Service |
The source data does not say whether other firmware versions are affected.
Patch Status
The source material lists no patch, fixed version, or vendor advisory, and the vendor did not respond to the disclosure. The CVE is not listed in the CISA KEV catalog, so CISA has published no required action or due date for it. Anyone running the affected devices should treat them as unpatched and watch the references below for updates.
Sources
- NVD – CVE-2026-100886
- VulDB – CVE-2026-100886
- VulDB – Vulnerability 410835
- VulDB – Vulnerability 410835 CTI
- VulDB – Submission 916434
- GitHub – heapframe/seetong-ts81xxd3x-rce
- CISA – Known Exploited Vulnerabilities Catalog (checked 2026-09-27; no entry for CVE-2026-100886)