CVE-2026-3893

CRITICAL

Carlson Software VASCO-B GNSS Receiver Missing Authentication for Critical Function

Title source: cna
STIX 2.1

Description

The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials.

Scores

CVSS v3 9.4
EPSS 0.0006
EPSS Percentile 19.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
Carlson Software/VASCO-B GNSS Receiver < 1.4.0
Carlson Software/VASCO-B GNSS Receiver 1.4.0
Published Apr 28, 2026
Tracked Since Apr 29, 2026