---
id: CVE-2026-33367
title: >-
  SNMP can be used to perform administrative actions such as retrieving
  configuration files, modifying user accounts or device settings, and
  initiating firmware or bootloader upgrades or downgrades—all without any
  authentication.
summary: >-
  SNMP can be used to perform administrative actions such as retrieving
  configuration files, modifying user accounts or device settings, and
  initiating firmware or bootloader upgrades or downgrades—all without any
  authentication.
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-306
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T17:29:33.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33367'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.hms-networks.com/'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.hms-networks.com/cybersecurity'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
ingestedAt: '2026-10-09T16:02:33.388Z'
---

## Overview

SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
