Security/ ics · rockwell automation · vulnerabilities · critical infrastructure

Rockwell Industrial Adapters Let Anyone Change Admin Passwords

A 9.4-severity authentication flaw in Rockwell's factory-floor adapters lets any network attacker change the device password with a single HTTP request.

Two security flaws in Rockwell Automation's FLEX I/O EtherNet/IP adapters could let a remote attacker take over the web interface or knock the device offline — no credentials required.

CISA flagged two vulnerabilities in the 1794-AENTR and 1794-AENTRXT adapters running firmware V2.012, hardware deployed in critical manufacturing environments worldwide. The worse of the two, CVE-2026-0647, carries a CVSS 3.1 score of 9.4 (Critical): a network-reachable attacker can send a crafted HTTP GET request to a specific endpoint and change the device's web interface password without ever authenticating. One request, full account takeover. The second flaw, CVE-2026-0646, exploits improper memory handling of CIP protocol requests to trigger a denial-of-service that severs the adapter's connection to its I/O modules and requires a manual reset to recover; it scores 7.5 (High). Rockwell Automation reported both flaws to CISA and has issued firmware version 2.013 to address them.

EtherNet/IP adapters sit at the junction of plant-floor hardware and plant-wide networking — a takeover here gives an attacker potential influence over the I/O modules controlling physical equipment. An authentication bypass triggered by a single GET request is not a sophisticated attack, which means the barrier to exploitation is unusually low for a device class that often runs in air-gap-optional environments.

No public exploitation has been reported as of the advisory date, but ICS authentication-bypass flaws tend to have a short window between disclosure and attempted abuse — operators on V2.012 should treat the update as urgent rather than routine.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →