Summary
CVE-2026-15706 is a missing authentication for critical function vulnerability (CWE-306) in Baylan Measuring Instruments Industry and Trade Inc.’s Smart Meter Management Application (BMS). The flaw allows an unauthenticated remote attacker to bypass authentication controls on critical management functions of the application. It carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: the BMS management API does not enforce authentication on critical functions, allowing access to operations that should require verified credentials.
- Trigger conditions: no privileges or user interaction are required; the affected functionality is reachable directly over the network.
- Attack vector: Network (AV:N), with low attack complexity (AC:L).
- Impact: successful exploitation yields high impact to confidentiality, integrity, and availability (C:H/I:H/A:H), potentially allowing an attacker to bypass authentication and access or manipulate smart meter management functions.
Affected software
- Baylan Smart Meter Management Application (BMS) — all versions before v1.1.10.142
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade Baylan Smart Meter Management Application (BMS) to v1.1.10.142 or later.
- If patching is not immediately possible: restrict network access to the BMS management interface to trusted internal networks only, and remove any direct internet exposure of the application until the upgrade is applied.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Baylan AMR | Login - Loaded script URL:
/Scripts/baylan.amr.global.min.js - Raw response body, when the script above is also loaded:
Ver.followed by a version number in a<span>element

