Tuesday, September 29, 2026

7 Advisories Published – 9-29-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Viidure, MikroTik, Anjvision, Baicells, VIVOTEK, TopTech, and Lantronix. 

Advisories  

Viidure Advisory - This advisory describes two vulnerabilities in the Viidure Dashcam Android Application. The vulnerabilities were reported to CISA by Bugrahan Karahan. CISA notes that: “Viidure did not respond to CISA's coordination attempts.” 

Mikrotik Advisory - This advisory describes an integer underflow vulnerability in the MikroTik RouterOS. The vulnerability was reported to CISA by an anonymous researcher.  

Anjvision Advisory -This advisory describes an initialization of resource with an insecure default vulnerability in the Anjvision YSSD-RTMP-H5 firmware. The vulnerabilities were reported to CISA by Andrew Lee. CISA notes that: “Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities.” 

Baicells Advisory - This advisory describes an uncaught exception vulnerability in the Baicells Technologies Nova 430H eNodeB. The vulnerability was reported to CISA by Qiqing Huang. CISA notes that: “Baicells has not responded to requests to work with CISA to mitigate this vulnerability.” 

VIVOTEK Advisory - This advisory describes a command injection vulnerability in the VIVOTEK Camera Firmware. The vulnerability was originally reported by Larry Cashdollar with proof-of-concept code. 

Toptech Advisory - This advisory describes 10 vulnerabilities in the Toptech Systems TMS7 and Tophat 7 terminal management systems. The vulnerabilities were reported by Sachin Shetty and Roy Duisters of Shell CyberDefence. 

Lantronix Advisory - This advisory describes two vulnerabilities in the Lantronix G520 Series Cellular Gateway. The vulnerabilities were reported to CISA by Ievgen Bondarenko. 

FRA Sends Safety System Info Protection NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOT’s Federal Railroad Administration (FRA) on “Litigation Protections for System Safety Program and Risk Reduction Program Information”. 

According to the 2026 Unified Agenda entry for this rulemaking:  

“This rulemaking would propose revising 49 CFR 270.105 and 271.11 [links added] to broaden the scope of railroad safety risk reduction program information protected from use in litigation.  The rulemaking would do so by removing the limitation that the protected information must have been compiled or collected solely” for a railroad safety risk reduction program purpose.” 

It would appear that this rulemaking is proceeding under the authority of 49 USC 20119. That section required DOT to conduct a study to determine if: 

“(I)t is in the public interest, including public safety and the legal rights of persons injured in railroad accidents, to withhold from discovery or admission into evidence in a Federal or State court proceeding for damages involving personal injury or wrongful death against a carrier any report, survey, schedule, list, or data compiled or collected for the purpose of evaluating, planning, or implementing a railroad safety risk reduction program required under this chapter, including a railroad carrier’s analysis of its safety risks and its statement of the mitigation measures with which it will address those risks” 

Such a study would have been conducted before the two CFR sections were adopted in 2020. It will be interesting to see if the FRA is relying on that original study for this amendment, or if it has conducted a new study. It would seem to me that a firmer foundation for this revision would be a new study. I would expect that victims’ rights and many rail safety organizations would be leery of any expansion of the information protections involved. 

Saturday, September 26, 2026

CISA Adds Mikrotik Vulnerability to KEV Catalog – 9-25-26

Yesterday, CISA announced that it had added an improper enforcement of behavioral Workflow vulnerability in the Mikrotik RouterOS to their Known Exploited Vulnerabilities (KEV) catalog. CERT-PL announced this vulnerability (along with five others) on September 5th, 2026. Mikrotik released three new versions (here, here, and here) that mitigate the vulnerability on September 3rd, 2026, with further updates released on September 22nd.  

On September 4th, Nick Pratley published a technical analysis of the Mikrotik vulnerability based upon his version differential analysis (using AI tools to speed the analysis); includes a limited effect proof-of-concept code. On September 17th, Bishop Fox published an article describing evidence that the six vulnerabilities were being exploited in the wild before Mikrotik published their updated versions, confirming a similar report from CERT.PL published on September 5th, 2026. 

CISA is requiring federal agencies to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements” [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” A compliance deadline of September 28th, 2026, has been established. 

Review – Bills Introduced – 9-24-26

 On Thursday, with the Senate in Washington (and preparing to leave for the weekend) and the House meeting in pro forma session, there were 188 bills introduced. Four of those bills may receive additional coverage in this blog:  

HR 10569 To amend the Homeland Security Act of 2002 to provide for the protection of biotechnology and biomanufacturing infrastructure by the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes. Khanna, Ro [Rep.-D-CA-17]    

S 5502 A bill to amend the Homeland Security Act of 2002 to provide for the protection of biotechnology and biomanufacturing infrastructure by the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes. Hassan, Margaret Wood [Sen.-D-NH]    

S 5508 A bill to establish a public-private working group to develop cybersecurity best practices for telecommunications carriers and related supply chain participants, and for other purposes. Warner, Mark R. [Sen.-D-VA]    

S 5541 A bill to establish the Cybersecurity and AI Board of Investigations, and for other purposes. Markey, Edward J. [Sen.-D-MA]     


For more information on these bills, including legislative history for similar bills in the 118th Congress, as well as a mention in passing of a bill to address the latest supply chain cybersecurity issue, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-9-24-26 - subscription required. 

 
/* Use this with templates/template-twocol.html */