SYS::ONLINE
Wasteland.
Briefs1677
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-11849 2026-06-12

IEI iRM-IEI Remote Management Hardcoded Credentials (CVE-2026-11849)

"A critical hardcoded-credentials flaw in IEI Integration Corp's iRM-IEI Remote Management lets unauthenticated remote attackers gain administrative control over the product's database."

A critical hardcoded-credentials flaw in IEI Integration Corp's iRM-IEI Remote Management lets unauthenticated remote attackers gain administrative control over the product's database.

What Is It

CVE-2026-11849 is a hardcoded credentials vulnerability (CWE-798) in the iRM-IEI Remote Management product developed by IEI Integration Corp. According to the NVD record, hard-coded credentials embedded in the product allow unauthenticated remote attackers to authenticate and gain administrative privileges on the database. The flaw was published on 2026-06-12 and was reported through TWCERT/CC ([email protected]).

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with a secondary CVSS 4.0 score of 9.3 (CRITICAL). The attack vector is network-based (AV:N) with low attack complexity (AC:L), requiring no privileges (PR:N) and no user interaction (UI:N). Confidentiality, integrity, and availability impacts are all rated HIGH. Because attackers can reach the system over the network and use built-in credentials with no authentication of their own, exploitation requires no special access and yields full administrative control of the database; a complete compromise of stored data.

What's Vulnerable

The affected product is IEI Integration Corp's iRM-IEI Remote Management. The supplied NVD record lists no specific affected version ranges or CPEs, so confirmation of impacted versions should be sought from the vendor and TWCERT/CC advisories below.

Patch Status

The supplied source material does not include a CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the provided data. The NVD status is "Received." No patch details, fixed versions, or specific remediation steps are present in the supplied data; refer to the TWCERT/CC advisories for vendor guidance and mitigation.

Sources