Security Advisory

CVE-2026-82567

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-15 21:45:45
Last updated 2026-09-16 18:11:13
Assigner icscert
CVSS score 6.3
State PUBLISHED

Description

The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem.