CVE-2026-13743

LOW

Improper verification of cryptographic signature in CubeSpace CW0057 Reaction Wheel

Title source: cna
STIX 2.1

Description

CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptographic Signature vulnerability. This could allow an attacker with physical access to the product to upload arbitrary malicious firmware to the device without authentication.

References (1)

Core 1
Core References
Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-02

Scores

CVSS v4 3.3
EPSS 0.0012
EPSS Percentile 1.9%
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (1)
CubeSpace/CW0057 Reaction Wheel < 5.0.20
Published Jul 02, 2026
Tracked Since Jul 03, 2026