Silex Technology's SD-330AC and AMC Manager were disclosed with two serious vulnerabilities that expose devices to remote compromise and unauthorized reconfiguration. The most severe issue, CVE-2026-32956, is a heap-based buffer overflow in redirect URL processing that can enable arbitrary code execution over the network without authentication or user interaction. The flaw is tracked as CWE-122 and carries a critical CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating full compromise of confidentiality, integrity, and availability is possible.
A second flaw, CVE-2026-32965, affects devices left in their factory-default state and allows them to be configured with a null string password, creating an insecure initialization condition. Classified as CWE-1188, the vulnerability is network-accessible and primarily threatens device integrity, with a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. The issues were reported through JPCERT/CC and published via JVN and Silex security advisories in Japanese and English, putting administrators on notice to review exposed deployments and initialization practices.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-21, CISA published ICS advisory ICSA-26-111-10 covering multiple vulnerabilities affecting Silex SD-330AC version 1.42 or earlier and AMC Manager version 5.0.2 or earlier. The advisory summarized severe impacts including remote code execution, denial of service, unauthorized configuration changes, and information disclosure, credited Francesco La Spina of Forescout as reporter, and said no known public exploitation had been reported.
On 2026-04-20, CVE-2026-32959 was recorded for Silex SD-330AC and AMC Manager as a weak cryptography vulnerability. The flaw could allow traffic information disclosure via a man-in-the-middle attack, and references were published in JVN and Silex security advisories.
On 2026-04-20, Silex disclosed that multiple vulnerabilities affecting SD-330AC and AMC Manager should be remediated by updating to SD-330AC firmware 1.50 or later and AMC Manager 5.1.0 or later. The advisory also recommended interim mitigations including disabling HTTP/HTTPS or SNMP services and setting a password on the settings web interface.
By 2026-04-20, public references for the vulnerabilities were available through JVN and Silex security advisories in Japanese and English. These advisories documented the affected products and technical classifications for the reported flaws.
On 2026-04-20, CVE-2026-32955 was recorded as a stack-based buffer overflow in redirect URL processing affecting Silex SD-330AC and AMC Manager. The flaw could allow arbitrary code execution, and public references were added to JVN and Silex security advisories.
On 2026-04-20, JPCERT/CC received a report of an insecure default initialization vulnerability affecting Silex SD-330AC and AMC Manager. In a factory-default network-connected state, the device could be configured with a null string password, creating a high-integrity risk.
On 2026-04-20, JPCERT/CC received a report of a heap-based buffer overflow in redirect URL processing affecting Silex SD-330AC and AMC Manager. The flaw could allow arbitrary code execution over the network without privileges or user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcejvn.jp
Open sourcesilex.jp
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.