Cyber & AI intelligence
Wasteland.
Briefs indexed2789
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-94493 2026-09-21

CVE-2026-94493: Missing Authentication in Gigatech PDV5701 WebSocket Service

"A critical, remotely exploitable missing-authentication flaw in the Gigatech PDV5701 (firmware 1.0.31_240305_112640) WebSocket Service carries a CVSS 3.1 base score of 10.0 and has a public exploit."

A critical, remotely exploitable missing-authentication flaw in the Gigatech PDV5701 (firmware 1.0.31_240305_112640) WebSocket Service carries a CVSS 3.1 base score of 10.0 and has a public exploit.

What Is It

CVE-2026-94493 is a missing authentication vulnerability affecting unknown processing of the file /index.html in the WebSocket Service component of the Gigatech PDV5701. The flaw is tracked under CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function). Manipulation of the affected handling results in missing authentication, and the attack can be launched remotely. The record was published by VulDB as the CNA and, as of 2026-09-21, sits in "Received" status at NVD.

Why It Matters

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, a base score of 10.0, CRITICAL. That means network attack vector, low complexity, no privileges, no user interaction, changed scope, and complete impact to confidentiality, integrity, and availability. The CVSS 4.0 secondary score is 9.3 (CRITICAL) with exploit maturity rated PROOF_OF_CONCEPT. CVSS 2.0 rates it 10.0 with complete impact across all three categories.

Per the NVD description, the exploit is now public and may be used. CVE-2026-94493 does not appear in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-21, so active exploitation is not confirmed by KEV at this time. Exploit maturity is currently rated proof-of-concept rather than weaponized or actively exploited, so the available public code does not by itself establish in-the-wild attacks. That said, a proof-of-concept against an unauthenticated, network-reachable service lowers the barrier to weaponization, and defenders with exposed PDV5701 units have reason to prioritize mitigation accordingly.

What's Vulnerable

Patch Status

Neither the NVD record nor the VulDB entry identifies a patch or fixed version, and because the CVE is absent from CISA's KEV catalog, no federal required action or remediation due date applies. The NVD record states the vendor was contacted early about this disclosure but did not respond in any way. Operators should assume no vendor fix is available and restrict network reachability to the affected WebSocket Service accordingly.

Sources