CVE-2026-70403

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

  • Published Sep 4, 2026
  • CVSS 9.3 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-70403 at the National Vulnerability Database