Today CISA’s NCCIC-ICS published 7 control system security advisories for products from Furuno, Ebyte, Bendix, PayRange, Siemens, Zoneminder, and Rently. They also updated advisories for products from Lantronix and Optigo.
Advisories
Furuno Advisory - This advisory describes two vulnerabilities in the FURUNO FA-50 Class B AIS Transponder. The vulnerabilities were reported to CISA by Souvik Kandar.
Ebyte Advisory - This advisory describes 11 vulnerabilities in the Ebyte NE2-D11 Firmware FW-9167-0-11. The vulnerability was reported to CISA by Jithin Nambiar.
Bendix Advisory - This advisory describes three vulnerabilities in the Bendix EC80 Brake ECU. The vulnerabilities were reported to CISA by Ben Gardiner of NMFTA.
PayRange Advisory - This advisory describes a missing authorization vulnerability in the PayRange API. The vulnerability was reported to CISA by Tahi Wilton Geary.
Siemens Advisory - This advisory describes a missing authentication for critical function vulnerability in the Siemens SIMATIC IoT2050 Advanced. The vulnerability was self-reported.
Zoneminder Advisory - This advisory describes an OS command injection vulnerability in the Zoneminder video surveillance system. Scriptkittens published an exploit for this vulnerability.
Rently Advisory - This advisory describes an insufficiently protected credentials vulnerability in the Rently Smart Home. The vulnerability was reported to CISA by Berk Dusunur.
Updates
Lantronix Update - This update provides additional information on the Lantronix EDS3000PS advisory that was originally published on March 10th, 2026.
Optigo Update - This update provides additional information on the Visual BACnet Capture Tool advisory that was originally published on March 11th, 2025.
For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-2-updates-published-054 - subscription required.
