Description
ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database. This issue has been fixed in version 2.4.18.029
Severity (CVSS)
| Base score | 5.3 |
|---|---|
| Severity | Medium |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-862 — CWE-862 Missing Authorization
Affected products
| Vendor | Product | Versions |
|---|---|---|
| ICU Scandinavia | Boomerang | 0 to <2.4.18.029 |
References
- https://cert.pl/posts/2026/07/CVE-2026-46458 (third-party-advisory)
- https://icuscandinavia.se/boomerang-quality-assurance-lab/ (product)
Generated from the official CVE List on 16 Jul 2026 07:01 UTC.