---
id: CVE-2026-9141
title: Taiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web Interface
summary: >-
  Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an
  authentication bypass vulnerability in the embedded web configuration
  interface that allows unauthenticated attackers to access internal application
  pages without any sessi…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-306
vendor: Taiko Network Communications Pte Ltd.
product: AG1000-01A SMS Alert Gateway
affected:
  - ag1000-01a_sms_alert_gateway Rev 7.3
  - ag1000-01a_sms_alert_gateway Rev 8
  - ag1000-01a_sms_alert_gateway UM-AG1000_R7.2
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-05-21T12:17:59.307105Z'
exploitAvailable: true
published: '2026-05-20'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:22:19.117Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-9141'
references:
  - url: >-
      https://medium.com/@forgetmen0t/multiple-vulnerabilities-in-taiko-ag1000-01a-sms-alert-gateway-82095b1d633e
    label: Ledger Security Bulletin 019
  - url: >-
      https://www.vulncheck.com/advisories/taiko-ag1000-01a-rev-8-authentication-bypass-via-web-interface
tags:
  - cve.org
  - exploit-available
epss: 0.00481
epssPercentile: 0.40686
ingestedAt: '2026-09-24T15:45:56.681Z'
---

## Overview

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access internal application pages without any session management or server-side authentication checks. Attackers with network access can directly request internal resources such as index.zhtml, point.zhtml, and log.shtml to gain full administrative read and write access, enabling unauthorized modification of alarm routing, device configuration, and disruption of monitoring and control functions.

## Affected

- `ag1000-01a_sms_alert_gateway Rev 7.3`
- `ag1000-01a_sms_alert_gateway Rev 8`
- `ag1000-01a_sms_alert_gateway UM-AG1000_R7.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
