Hard-coded SNMP creds in Schneider device enable unauth access
CVE-2026-4832 Published on April 14, 2026

CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.

NVD

Weakness Type

Use of Hard-coded Credentials

The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.


Affected Versions

Schneider Electric Easergy MiCOM P14x: Schneider Electric Easergy MiCOM P24x: Schneider Electric Easergy MiCOM P341: Schneider Electric Easergy MiCOM P342, P343, P344, P345: Schneider Electric Easergy MiCOM P442, P444: Schneider Electric Easergy MiCOM P443, P445, P446, P543, P544, P545, P546: Schneider Electric Easergy MiCOM P642, P645: Schneider Electric Easergy MiCOM P643: Schneider Electric Easergy MiCOM P741, P742, P743: Schneider Electric Easergy MiCOM P746: Schneider Electric Easergy MiCOM P841: Schneider Electric Easergy MiCOM P849: