An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.CreditsShorabh Karir and Deepak Singh of KPMG reported these vulnerabilities to CISAReferenceshttps://www.cisa.gov/news-events/ics-advisories/icsa-26-041-02https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-041-02.jsonhttps://www.zlmcu.com/en/contact_us.htm