{"id":"CVE-2026-93291","published":"2026-09-24T20:17:34.463","lastModified":"2026-09-24T21:25:27.050","description":"Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.","cvssScore":9.4,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","cwes":["CWE-295"],"vendors":[],"products":[],"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"Omni C20 fails to validate certificates, allowing attackers to perform man-in-the-middle attacks and potentially execute arbitrary code.","exploitability":"Exploitation requires control over the network path between the client and server, making it moderately difficult.","blast_radius":"If exploited, this flaw could lead to unauthorized code execution on affected devices, with severe consequences.","remediation":"Disable the affected feature or upgrade to the latest version of Omni C20.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","ssl","network","mitm"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:49:16.299Z"}}