Showing posts with label WHILL. Show all posts
Showing posts with label WHILL. Show all posts

Thursday, July 2, 2026

Review – 3 Advisories and 3 Updates Published – 7-2-26

Today CISA’s NCCIC-ICS published three control system security advisories for products from Gardyn, CubeSpace, and ST Engineering. They updated two control system advisories for products from Gardyn and Mitsubishi. They also updated a medical device security advisory for products from WHILL. 

Advisories  

Gardyn Advisory - This advisory describes three vulnerabilities in the Gardyn IoT Hub. 

CubeSpace Advisory - This advisory describes an improper verification of cryptographic signature vulnerability in the CubeSpace CW0057 Reaction Wheel. 

ST Engineering Advisory - This advisory describes two vulnerabilities in the ST Engineering iDirect iQ-Series Terminals. 

Updates  

Gardyn Update - This update provides additional information on the Home Kit advisory that was originally published on February 24, 2026, and most recently updated on April 2nd, 2026. 

Mitsubishi Update - This update provides additional information on the CNC Series advisory that was originally published on October 17th, 2024, and most recently updated on December 18th, 2025. 

WHILL Update - This update provides additional information on the C2 Electric Wheelchairs advisory that was originally published on December 30th, 2025, and most recently updated on March 24th, 2026. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-3-updates-published-2e9 - subscription required. 

Tuesday, March 24, 2026

Review – 4 Advisories and 1 Update Published – 3-24-26

Today CISA’s NCCIC-ICS published three control system security advisories for products from Schneider (2) and Pharos Controls. They published a medical device security advisory for products from Grassroots.

Advisories

Schneider Advisory #1 - This advisory discusses four vulnerabilities (with publicly available exploit) in the Schneider Plant iT/Brewmaxx product.

Schneider Advisory #2 - This advisory describes a deserialization of untrusted data vulnerability in the Schneider EcoStruxure Foxboro DCS.

Pharos Advisory - This advisory describes a missing authentication for critical function vulnerability in the Pharos Mosaic Show Controller.

Grassroots Advisory - This advisory describes a missing release of memory after effective lifetime vulnerability in the Grassroots DICOM library.

Updates

WHILL Update - This update provides additional information on the Model C2 Electric Wheelchairs advisory that was originally reported on December 30th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-1-update-published-2f7 - subscription required.

Tuesday, December 30, 2025

Review – 1 Advisory and 1 Update Published – 12-30-25

Today CISA’s NCCIC-ICS published a control system security advisory for products from WHILL. They also updated an advisory for products from AzeoTech.

Advisories

WHILL Advisory - This advisory describes a missing authentication for critical function vulnerability in the WHILL Model C2 Electric Wheelchairs and Model F Power Chairs.

Updates

AzeoTech Update - This update provides additional information on the DAQFactory advisory that was originally published on December 11th, 2025.

 

For more information on these advisories, including a down-the-rabbit-hole look at missing vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-1-update-published-d1d - subscription required.
 
/* Use this with templates/template-twocol.html */