New CVE-2026-1201 (platform vulnerability was fixed in Aug 2025)

This is legit, I've been communicating with a number of people at CERT Vulnerability Notes Database to acknowledge and to backfill the information. It's not public yet, as far as I can tell in VINCE.

The issue has been reported privately and is fixed in firmware build 2.4.2.157: Release 2.4.2 Available - #10 by gopher.ny.

In a nutshell, if you have a functioning link to a single dashboard, you can use some crafty ways to access other dashboards and to control devices that the original dashboard has no permissions to.