The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.CreditsScot Berner of TrustedSec reported this vulnerability to CISA.Referenceshttps://digital-watchdog.com/downloads/https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-01.json