TroutTrout
Back to Blog
ICS AdvisoriesOT SecurityNetwork SecurityManufacturingRemote Access

Red Lion N-Tron 700 Switches: Patch, Then Lock the Admin Interface (ICSA-26-281-01)

Trout Team9 min read

The short version.

On October 8, 2026, CISA published ICSA-26-281-01 for Red Lion Controls N-Tron 700 Series managed industrial Ethernet switches. It covers seven CVEs in firmware 3.11.0 and earlier and bootloader 2.0.6.1 and earlier. The highest scores are CVSS v3.1 8.3 and CVSS v4.0 9.3.

This time the network gear itself is the target. A default admin account stays enabled after you add your own. Passwords sit in the configuration file in plaintext. SNMP can change accounts, pull the configuration and push firmware without a login. One URL reboots the switch.

The fix is firmware 3.11.1 or later. Then make the switch's web interface, SSH and SNMP reachable only from the people and stations that need them. CISA says no known public exploitation has been reported to it.

Why a managed switch matters.

An industrial switch connects the PLCs, HMIs, drives and historians on a production line. Every control message on that segment crosses it.

A managed switch also has its own admin interface: a web GUI, a command line, SNMP for monitoring. Whoever controls that interface controls the network around it. They can change VLANs and port settings, read the configuration, or take the switch down. When a switch reboots, everything behind it loses its connection until it comes back.

Switches are also easy to forget. They rarely appear on a patch list next to the PLCs, and their default accounts often survive commissioning.

What the advisory says.

  • Product: Red Lion Controls N-Tron 700 Series. Firmware 3.11.0 and earlier, bootloader 2.0.6.1 and earlier.
  • Fix: firmware 3.11.1 or later.
  • Sectors: Commercial Facilities, Communications, Critical Manufacturing, Information Technology. Deployed worldwide.
  • Reported by: Gabrianna (Ria) Milloway of Idaho National Laboratory.
CVECVSS v3.1CVSS v4.0What it allows, per the advisoryAccess in the v3.1 vector
CVE-2026-326456.09.2Default admin credentials stay enabled after other admin accounts are configured (CWE-798)Local, high privileges
CVE-2026-394608.19.3Usernames and passwords stored in plaintext in the configuration file, which can be exported by TFTP (CWE-522)Network, low privileges
CVE-2026-287457.59.3Passwords stored with weak encryption, so known default credentials expose the others (CWE-257)Network, no privileges
CVE-2026-333678.19.3SNMP performs admin actions, including firmware upgrades and downgrades, with no authentication (CWE-306)Network, low privileges
CVE-2026-297977.18.4Firmware and bootloader updates need no authentication and no integrity check (CWE-494)Network, low privileges
CVE-2026-394538.38.5A specific URL on the web server reboots the switch, and can be scripted (CWE-617)Network, low privileges
CVE-2026-332724.96.8With physical access, boot from factory settings, log in with the default admin, and keep the changes (CWE-288)Physical, low privileges

Read the SNMP row closely. The description says no authentication is needed. The v3.1 vector scores it with low privileges. Treat SNMP access to the switch as admin access either way.

How the flaws chain together.

The flaws are worse together than alone.

The default admin is the way in. It stays enabled after commissioning, so a switch set up with new accounts still accepts the factory login.

Then every password comes out. Logged in as admin, the configuration file can be read from the command line or exported by TFTP from the web interface. It holds usernames and passwords in plaintext. SNMP can start the same TFTP export without a login. TFTP itself carries the file across the network unencrypted.

Then the switch can be changed or stopped. SNMP can modify user accounts and settings, and start firmware or bootloader upgrades or downgrades. The advisory says anyone with the same software can scan a network for N-Tron devices and push or pull firmware by SNMP and TFTP. Separately, one URL on the web server reboots the switch, and a script can keep it rebooting.

The table maps the flaws to MITRE ATT&CK for ICS. It describes what the flaws allow, not an observed attack. ATT&CK for ICS v19 moved Default Credentials and System Firmware to new IDs, shown with the old ones.

TacticTechnique (ID)How it applies here
DiscoveryRemote System Discovery (T0846)Scanning a network for N-Tron devices, as the advisory describes
Lateral Movement, PersistenceDefault Credentials (T1694.001, formerly T0812)The factory admin account that persists, CVE-2026-32645
DiscoveryNetwork Sniffing (T0842)Conditional: capturing a configuration file with plaintext passwords as it crosses the network by TFTP
Lateral Movement, PersistenceValid Accounts (T0859)Reusing passwords recovered from the configuration file
Persistence, Inhibit Response FunctionSystem Firmware (T1693.001, formerly T0857)Pushing firmware or bootloader images with no authentication or integrity check
Inhibit Response FunctionDenial of Service (T0814)The scripted reboot URL, CVE-2026-39453
ImpactLoss of View (T0829)Possible consequence: HMIs and SCADA lose their link while the switch keeps rebooting

What to do before and after the update.

Start with the vendor's and CISA's steps. Update to firmware 3.11.1 or later, following Red Lion's upgrade procedure. Where you cannot update yet, configure or disable the SNMP communities and disable access to the web GUI. CISA also asks you to keep control system devices off the internet, put them behind firewalls away from the business network, and use a secure method such as a VPN when remote access is needed.

Change every password on the switch. Treat any password stored on an affected switch as known, because the configuration file holds it in plaintext. That includes passwords reused on other equipment.

Separate the management plane from the control traffic. Put the switches' management addresses in their own segment. The switch keeps forwarding PLC and HMI traffic as before. Only the admin path moves.

Decide who needs each service. One admin workstation needs the web GUI and SSH. The monitoring station needs SNMP. Nobody else needs any of the three.

How Access Gate helps, and its limits.

Two panels. Today: any host that reaches an N-Tron 700 switch can use the web GUI, SNMP and TFTP, leading to admin access, password theft, firmware pushes or repeated reboots. With Access Gate: only a named user on the admin workstation and the monitoring station reach the switch, everyone else has no route.
Who can reach the N-Tron 700 management plane today, and with a gate after the update.

Access Gate is an appliance installed at each site. It connects to your existing network, beside it. You then steer the switches' management traffic through it, one switch or one subnet at a time. Nothing is installed on the switches. It is installed in a day per site.

Once the traffic flows through the gate, four documented features do the work.

A named person signs in first. An access screen asks the admin to log in with their own directory account before the workstation reaches any switch. Access expires after a preset timeout.

A per-machine rule decides the rest. Access control lists are default deny. One rule allows the admin workstation to reach the switch on HTTPS and SSH. Another allows the monitoring station on SNMP. Every other host gets no route to the management plane, which also keeps the reboot URL and the SNMP admin actions out of reach.

Admin sessions are recorded. With privileged access management, the admin opens the switch's web GUI or SSH in a browser session tied to their name. The session is time-limited and recorded. Where the switch's web interface lacks encryption, the gate can wrap it in TLS, so the login does not cross the network in clear.

Every rule change is kept. The enclave change history records who changed which rule and when. If you run many switches across plants, those rule changes can be driven from your LLM on Access Gate Performance.

The limits are real. Access Gate does not fix the firmware: 3.11.1 is still the fix. The admin who is allowed in still reaches a vulnerable web server until the update. A host already plugged into the switch management segment, outside the gate, is outside its control. The physical-access flaw needs a locked cabinet. And a password that already leaked must still be changed.

For the wider design, see OT network security, OT identity and secure remote access.

What to do this week.

  1. List every N-Tron 700 switch with its firmware and bootloader versions.
  2. Test who can reach each one on the web GUI, SSH and SNMP, from the corporate network and from the internet.
  3. Configure or disable SNMP communities, and disable the web GUI where you do not need it.
  4. Download firmware 3.11.1 and schedule the update with the line it serves.
  5. Change every password stored on the switches, and any reuse of them elsewhere.
  6. Restrict the management plane to one admin workstation and the monitoring station.
  7. Lock the cabinets that hold the switches.

Want to see where a gate would sit at your plant? Build your network in a few minutes. Every other advisory we have covered is in the ICS security advisories archive.


Sources: CISA ICS Advisory ICSA-26-281-01 (October 8, 2026) and its CSAF record; the HMS Networks cybersecurity page linked from the advisory; the CISA Known Exploited Vulnerabilities catalog, checked October 9, 2026; and MITRE ATT&CK for ICS v19. Confirm affected versions and the upgrade procedure with Red Lion before changing a production switch.

FAQ

Frequently Asked Questions

What is CISA advisory ICSA-26-281-01?
It is an ICS advisory CISA published on October 8, 2026 for Red Lion Controls N-Tron 700 Series managed industrial Ethernet switches. It covers seven CVEs in firmware 3.11.0 and earlier and bootloader 2.0.6.1 and earlier. The highest scores are CVSS v3.1 8.3 and CVSS v4.0 9.3. CISA lists the Commercial Facilities, Communications, Critical Manufacturing and Information Technology sectors, with worldwide deployment.
Which N-Tron 700 firmware fixes the vulnerabilities?
Firmware 3.11.1 or later. The advisory lists firmware 3.11.0 and earlier, and bootloader 2.0.6.1 and earlier, as affected. Red Lion publishes an upgrade procedure document, and CISA links to it and to the HMS Networks advisory on the same flaws.
What can an attacker do with the N-Tron 700 vulnerabilities?
Take over the switch. According to the advisory, an attacker can gain administrative access and view, edit and upload configuration files. SNMP can retrieve configuration files, change user accounts and settings, and start firmware or bootloader upgrades and downgrades without authentication. A specific URL on the web server reboots the switch, and a script can repeat it to keep the switch rebooting.
Are the N-Tron 700 vulnerabilities being exploited?
CISA states that no known public exploitation specifically targeting these vulnerabilities has been reported to it. None of the seven CVEs was in the CISA Known Exploited Vulnerabilities catalog when we checked on October 9, 2026. Check the catalog again before you set the priority of the update.
What should I do if I cannot update the switch firmware right away?
Apply CISA's listed mitigations: configure or disable the SNMP communities and disable access to the web GUI. Keep the switch off the internet and behind a firewall, away from the business network. Then allow the management interfaces only from the hosts that need them, such as one admin workstation and the monitoring station, with each person signing in under their own name.
Does changing the default password fix CVE-2026-32645?
Not on its own. The advisory says the default factory credentials with administrative access stay enabled even after you configure other administrator accounts. Adding your own admin account does not remove them. Firmware 3.11.1 is the fix, and until it is installed the useful control is limiting who can reach the switch's management interfaces.

Other Articles

ICS AdvisoriesPower Grid

openPDC and openHistorian Flaws: Patch, Then Gate the Historian (ICSA-26-281-02)

CISA's ICSA-26-281-02 covers six CVEs in Grid Protection Alliance openPDC and openHistorian, the open-source phasor data concentrator and historian used by utilities. The worst, CVSS 9.8, lets an unauthenticated attacker run code through the service console. Patches exist, but upgraded installs keep their old network bindings and the Docker image gets no fix, so the second job is to control who can reach the server.

ICS AdvisoriesOT Security

Serial-to-IP Device Servers: Four CISA Advisories in Three Days

Between August 25 and August 27, 2026, CISA published four advisories against the same narrow device class: Update A to ICSA-26-069-02 for the Lantronix EDS lines, ICSA-26-237-06 for the Ebyte NE2-D11, then ICSA-26-239-05 for the Ebyte NA111-M and ICSA-26-239-01 for the Xiiaozet LK100W. One device class, three days, and a component that almost never appears in an OT asset inventory as a networked device.

OT SecurityFirewalls

How to manage OT firewall rules at scale with your LLM and Access Gate

Firewall rules written one by one, plant by plant, take weeks and drift. Security vendors are moving to AI agents. On a control network you want the enforcement on the wire and a human approving every write. This is how that works with Access Gate.