ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database.
This issue has been fixed in version 2.4.18.029
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-15 13:17
Updated : 2026-07-15 18:03
NVD link : CVE-2026-46459
Mitre link : CVE-2026-46459
CVE.ORG link : CVE-2026-46459
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
