Labkotec LID-3300IP

Summary

A vulnerability, CVE-2026-1775, has been identified in the Labkotec LID-3300IP ice detector, allowing unauthenticated attackers to alter device parameters and execute commands. Successful exploitation could lead to disruption of operations and potential safety hazards in critical infrastructure sectors. Labkotec recommends updating to the LID-3300IP Type 2 model with firmware V2.40 and enabling HTTPS for network traffic, while also suggesting network segmentation for devices not connected to Ethernet.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to gain control of critical infrastructure systems, posing a direct threat to operational functionality and safety.

Severity

9.4 Critical

Defender Context

This alert highlights a critical vulnerability in industrial control systems (ICS) used in communications and energy sectors. Defenders must prioritize patching or upgrading affected Labkotec LID-3300IP devices and ensure network segmentation to protect against unauthorized access and potential operational disruptions. Monitoring for specially crafted packets targeting these devices is also crucial.

Read Full Story →