CVE-2026-1840 Details
Description
The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes essential configuration settings, allowing attackers to alter operational parameters and trigger system restarts without restriction. Such unauthorized changes can disrupt normal functionality and, if performed repeatedly, may lead to a loss of communications to the device.
A vulnerability exists in the Aclara Metrum Cellular Web Interface due to a lack of authentication on critical system functions. This flaw allows unauthorized access to important configuration settings, enabling attackers to modify operational parameters and initiate system restarts without any restrictions. Such unauthorized modifications can interfere with normal operations, and if done repeatedly, may disrupt communication with the device.
Users are advised to update their firmware to version 2.1.0.105. This version can be downloaded from Aclara Connect.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aclara.my.site.com/AclaraConnect/s/ | [email protected] | Permission RequiredVendor |
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-174-07.json | [email protected] | AdvisoryRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-07 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Hubbell Aclara Metrum Cellular Web Interface | < v2.1.0.105 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion