Cyber & AI intelligence
Wasteland.
Briefs indexed2904
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-100886 2026-09-27

Seetong T8100/T8200-Series Debug Service Authentication Flaw (CVE-2026-100886)

"CVE-2026-100886 is a critical improper authentication flaw in the Debug Service of several Seetong T-series devices; it can be exploited remotely without credentials, and a public exploit is available."

CVE-2026-100886 is a critical improper authentication flaw in the Debug Service of several Seetong T-series devices; it can be exploited remotely without credentials, and a public exploit is available.

What Is It

CVE-2026-100886 is an improper authentication vulnerability (CWE-287) in an unspecified function of the Debug Service component on Seetong T8108, T8108P, T8116, and T8232 devices. VulDB is the assigning CNA. The record was published to NVD on 2026-09-27 and currently has "Received" status, which means NVD has not yet analyzed it.

The CNA's CVSS v3.1 score is 10.0 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The CVSS v4.0 score is 9.3 (CRITICAL), and the CVSS v2 score is 10.0.

Why It Matters

As of 2026-09-27, the CISA Known Exploited Vulnerabilities (KEV) catalog has no entry for this CVE, so KEV does not currently confirm active exploitation.

What's Vulnerable

These Seetong products are affected, all at firmware version 4.6.1.4-build202604241011:

Product Affected Module
T8108 Debug Service
T8108P Debug Service
T8116 Debug Service
T8232 Debug Service

The source data does not say whether other firmware versions are affected.

Patch Status

The source material lists no patch, fixed version, or vendor advisory, and the vendor did not respond to the disclosure. The CVE is not listed in the CISA KEV catalog, so CISA has published no required action or due date for it. Anyone running the affected devices should treat them as unpatched and watch the references below for updates.

Sources