A new federal security advisory has flagged seven vulnerabilities in Red Lion Controls' N-Tron 700 Series industrial switches, and the headline flaw is a hardcoded admin password that survives even after an administrator sets up a new account.
The advisory, published October 8, covers firmware up to version 3.11.0 and bootloader up to version 2.0.6.1. Beyond the persistent factory credential, the switches store usernames and passwords in plaintext inside configuration files, and those files can be pulled off the device through an unauthenticated SNMP-triggered TFTP transfer. Other stored credentials use weak encryption, and a missing-authentication bug lets an attacker reboot the switch just by hitting a specific URL, something that can be scripted into a loop for a denial-of-service attack. The combined flaws earn a CVSS v3.1 score of 8.3, and vendor HMS Networks has shipped firmware 3.11.1 as the fix.
N-Tron switches sit inside commercial facilities, communications networks, critical manufacturing plants, and IT infrastructure worldwide, the kind of unglamorous gear nobody audits until it becomes the way in. A password that persists through account changes isn't really a bug so much as a design assumption that never accounted for an attacker reading the manual.
Industrial switch vendors keep shipping hardcoded credentials as if Stuxnet never happened; patching them, unlike patching a laptop, means someone has to physically walk onto a factory floor.