securityonline.info 6 Oct 2026, 10:42 UTC

Critical AAS Edge Client flaw lets network attackers alter industrial data

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CERT @VDE has disclosed CVE-2026-94293, a critical flaw in Murrelektronik’s AAS Edge Client. The advisory assigns a CVSS v3.1 score of 9.8 (Critical) and states that all versions of the aas-edge-client are affected by missing authentication in a key REST API function. The article notes that the AAS Edge Client is a reference application for the Asset Administration Shell (AAS) standard used in Industry 4.0, but it was never intended for production use and is no longer maintained.

The code remains publicly available or copied in some labs, though Murrelektronik has since archived the repository and private’d its GitHub organisation.

The vulnerability exists because the app’s REST API listens on TCP port 18000 on all interfaces, requires no authentication, and accepts cross-origin requests from any origin. This implies that an attacker on the same network could read exposed data and alter AAS submodel data, with the edge client forwarding changes to the central AAS server.

While CERT@VDE warns that manipulated data could be ingested by systems relying on the central server, the article records that there is no confirmed exploitation in the wild at this time. There is no patch forthcoming; Murrelektronik recommends discontinuing use, removing deployments, and eradicating copies of the source code and container images. The piece also suggests organisations should audit what the central AAS server received to detect any potentially altered data.

View full article

Article by CyberSIXT