


Perceptive Security
SOC/SIEM Consultancy

VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to o…
Published:
28 July 2026 at 22:00:00
Alert date:
29 July 2026 at 09:01:49
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Identity & Access
A Hidden Functionality vulnerability (CVE-2026-18191) has been identified in the Vacron VIN-DS783E-E6 network device. The flaw allows unauthenticated remote attackers to exploit a concealed function within the device to retrieve administrator credentials. No authentication is required to leverage this vulnerability, making it highly accessible to remote threat actors. Successful exploitation grants full administrative access to the affected device. The vulnerability was reported via TWCERT and published on NVD. Vacron is the manufacturer of the affected device. The severity is rated High due to the ease of exploitation and impact on credential confidentiality. Organizations using this device should apply patches or mitigations as soon as they become available.
Technical details
Mitigation steps:
Affected products:
Vacron VIN-DS783E-E6
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18191
https://www.twcert.org.tw/en/cp-139-11049-db9ae-2.html
https://www.twcert.org.tw/tw/cp-132-11048-c8ce2-1.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
