


Perceptive Security
SOC/SIEM Consultancy

The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism,
allowing an attacker with network access to directly access and modify
its configuration …
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 21:20:19
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure
The Carlson VASCO-B GNSS Receiver contains a critical security vulnerability where it lacks any authentication mechanism. This allows attackers with network access to directly access and modify the device's configuration and operational functions without requiring any credentials. The vulnerability affects GNSS receivers used in surveying and positioning applications, potentially allowing unauthorized control of critical positioning equipment. This represents a significant security flaw in industrial and surveying equipment that could be exploited remotely.
Technical details
Mitigation steps:
Affected products:
Carlson VASCO-B GNSS Receiver
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3893
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-02.json
https://www.carlsonsw.com/support-and-training/
https://www.cve.org/CVERecord?id=CVE-2026-3893
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
