CVE-2026-3587

CRITICAL

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

Affects 0 products across 1 vendor.

BCS6.64
CVSS 3.110.0
EPSS0.7%
Percentile49th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-912: CWE-912
Related Attack Patterns (CAPEC)
CAPEC-190 Reverse Engineer an Executable to Expose Assumed Hidden Functionality
via CWE-912
CAPEC-133 Try All Common Switches
via CWE-912

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

BSID: BS-2026-GLOBAL-273734-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-3587?
An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.
What is the CVSS score for CVE-2026-3587?
CVE-2026-3587 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.7%.
Is CVE-2026-3587 actively exploited?
No confirmed active exploitation of CVE-2026-3587 as of 2026-05-30.
How do I remediate CVE-2026-3587?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-3587?
CVE-2026-3587 affects: Full.
Vulnerability Details
CVE IDCVE-2026-3587
BSIDBS-2026-GLOBAL-273734-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2026-03-23
Last Modified2026-03-24
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector involves an unauthenticated remote attacker using a hidden function in the CLI prompt to bypass restrictions and gain full control over the device.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Full —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 134 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash0f4fb28644978664c8655ce91bd7a6948a6a84bae38a4104ecadc1861a778b76302c746fe9510787ea11b3e2af126f0464e73bfc4ec851520fd9b4a1655b375d
Related CVEs affecting Full
CVE-2025-12539 10.0 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensit... CVE-2026-3611 10.0 The Honeywell IQ4x building management controller, exposes its full web-based... CVE-2026-42869 10.0 SOCFortress CoPilot focuses on providing a single pane of glass for all your ... CVE-2026-42369 10.0 GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many su... CVE-2025-54122 10.0 Manager-io/Manager is accounting software. A critical unauthenticated full re...
View all Full CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →