CVE-2026-4436

HIGH

GPL Odorizers GPL750 Missing Authentication for Critical Function

Title source: cna

Description

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.

Scores

CVSS v3 8.6
EPSS 0.0006
EPSS Percentile 19.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Details

CWE
CWE-306
Status published
Products (4)
GPL Odorizers/GPL750 (XL4) v1.0 - v6.0
GPL Odorizers/GPL750 (XL4 Prime) v4.0 - v6.0
GPL Odorizers/GPL Odorizers GPL750 (XL7) v13.0 - v20.0
GPL Odorizers/GPL Odorizers GPL750 (XL7 Prime) v18.4 - v20.0
Published Apr 09, 2026
Tracked Since Apr 10, 2026