---
id: CVE-2026-33272
title: >-
  A malicious user with physical access to the device can boot the switch from
  factory settings without authentication, use the default administrative
  credentials to obtain administrative access, and save changes to the
  configuration file …
summary: >-
  A malicious user with physical access to the device can boot the switch from
  factory settings without authentication, use the default administrative
  credentials to obtain administrative access, and save changes to the
  configuration file …
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-288
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T17:29:33.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33272'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.hms-networks.com/'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.hms-networks.com/cybersecurity'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
ingestedAt: '2026-10-09T16:02:33.388Z'
---

## Overview

A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
