In the critical infrastructure ecosystem, protection relays such as Schneider Electric's Easergy MiCOM Px40 series play a fundamental role in monitoring and safeguarding medium, high, and extra-high voltage electrical networks. However, a vulnerability has recently been identified affecting multiple versions of these devices, related to the use of hard-coded credentials (CWE-798) that could expose sensitive information through the SNMP protocol. This finding, reported by Schneider Electric CPCERT to CISA, underscores the need to adopt robust cybersecurity measures in industrial environments.
The vulnerability, tracked as CVE-2026-4832, has a CVSS v3.1 score of 5.3 (medium severity) and is characterized by allowing an unauthenticated attacker to interrogate the device's SNMP port and obtain basic device identification information. Although the impact is limited to the disclosure of identification data (it does not compromise system integrity or availability), in the context of critical infrastructures any information leakage can be the first step toward more sophisticated attacks. The affected products cover a wide range of the MiCOM Px40 series, including the P14x, P24x, P341, P342–P345, P442–P446, P543–P546, P841, P643, P642/645, P741–P743, P746, and P849 models, in versions prior to those indicated in the official advisory.
The root cause lies in the inclusion of embedded credentials in the firmware that cannot be changed by the user. When the SNMP service is enabled, these hard-coded credentials allow any entity with network access to perform queries that reveal data such as manufacturer, model, or firmware version. Although it may seem like a minor exposure, in industrial automation and control environments such information can be used by malicious actors to plan targeted attacks, identify outdated or vulnerable equipment, or even as part of a broader reconnaissance campaign.
Schneider Electric has provided several mitigation options. For customers who do not require the SNMP protocol, the primary recommendation is to upgrade the firmware to a version that removes this functionality. If this is not possible, compensatory measures should be applied, such as using firewalls to segment the control network, employing VPN for remote access, and generally keeping the relays within a protected network environment isolated from the Internet. These practices are standard in any defense-in-depth strategy for industrial control systems (ICS).
Beyond immediate mitigation, this incident highlights the importance of integrating cybersecurity into the lifecycle of software and embedded systems. Companies managing critical infrastructures must not only apply patches but also review their network architectures, implement hardening policies, and consider adopting continuous monitoring solutions. In this regard, having a technology partner that understands both the particularities of OT environments and IT best practices is key to reducing the attack surface.
At Q2BSTUDIO, as a software development and technology company, we offer specialized industrial cybersecurity services including security audits, penetration testing, and device hardening consulting. Additionally, our experience in cloud computing (AWS and Azure) allows us to help organizations design secure hybrid architectures that keep control systems isolated while enabling the necessary connectivity for remote operation. If your organization needs to evaluate the security of your automation systems, we invite you to learn more about our cybersecurity and pentesting services.
The MiCOM Px40 vulnerability also reminds us that security by design must be a priority. The use of hard-coded credentials is an outdated practice that should be avoided in any modern development. At Q2BSTUDIO we apply secure coding principles in our custom software solutions, integrating robust access controls, multi-factor authentication, and data encryption. Likewise, our artificial intelligence and AI agent platforms incorporate security mechanisms to protect both the models and the sensitive data they process.
In parallel, data analytics and real-time monitoring are essential for detecting anomalous behavior on the network. The Business Intelligence (Power BI) solutions we develop allow visualization of security metrics, SNMP traffic, and industrial device events, facilitating informed decision-making. If your company is moving toward digital transformation of its processes, consider adopting a robust cloud platform; our cloud services on AWS and Azure are designed to meet the highest security and performance standards.
Finally, it is important to highlight that collaboration between manufacturers, integrators, and end users is essential to mitigate risks. Responsible disclosure of vulnerabilities like this allows the industrial community to take action before incidents occur. Affected organizations should prioritize firmware updates and network segmentation, but they should also take this opportunity to review their overall security posture. Implementing intrusion detection systems, training personnel, and hiring specialized cybersecurity services are investments that pay off quickly when a cyberattack is avoided.
At Q2BSTUDIO, we believe that technology should be a secure enabler for business. Whether through custom application development, integration of AI agents, cloud migration, or deployment of Power BI dashboards, our team is ready to accompany you on your journey to operational excellence with maximum security. Contact us for a personalized consultation and discover how we can help you protect your critical assets.





