Back

CRITICAL

Horner Automation Cscape and XL4, XL7 PLC Weak password requirements

Published Apr 17, 2026

Description

An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.

Affected products

Remediation

Vendor solution

Horner Automation recommends users update to Cscape v10.2 SP2 or later. Horner Automation has also released the latest firmware for both XL4 and XL7 PLCs. Horner recommends users update to the latest version of the firmware.  https://hornerautomation.com/cscape-software-free/cscape-software/

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Apr 17, 2026
Updated Apr 20, 2026
Reserved Apr 14, 2026
CISA Vulnrichment
Updated Apr 17, 2026
NVD
Status Awaiting Analysis
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a