Article

    Cyber News / Article / Vulnerabilities in ICU Scandinavia Boomerang software

    Vulnerabilities in ICU Scandinavia Boomerang software
    CE
    CERT Polska-2026-07-15

    Vulnerabilities in ICU Scandinavia Boomerang software

    CERT Polska has received a report about vulnerabilities in ICU Scandinavia Boomerang software and participated in coordination of their disclosure.

    The vulnerabilityCVE-2026-46458: ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows an unauthenticated remote attacker to retrieve plaintext service account and SMTP credentials by requesting specific XML files from the webroot.

    The vulnerabilityCVE-2026-46459: ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database.

    These issues have been fixed in version 2.4.18.029.

    We thank Marek Figielski (vanilla.pl) for the responsible vulnerability report.

    Original source