Summary
CVE-2026-18808 is a critical Improper Control of Generation of Code ("Code Injection", CWE-94) vulnerability affecting Klemsan Electrical Electronics Inc.’s KIO (Klemsan Internet Objects) IoT platform. The flaw allows an unauthenticated remote attacker to inject and execute arbitrary code on the affected system, resulting in unauthenticated Remote Code Execution (RCE). It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting network-exploitability with no authentication or user interaction required.
Technical details
- Root cause: KIO improperly controls the generation of code, permitting injected code to be processed and executed by the application (CWE-94 – Improper Control of Generation of Code / Code Injection, mapped to CAPEC-242).
- Trigger conditions: No authentication or user interaction is required to trigger the vulnerability, and attack complexity is rated Low.
- Attack vector: Network — the vulnerability can be exploited remotely over the network without any privileges.
- Impact: Successful exploitation results in unauthenticated Remote Code Execution, with High impact to confidentiality, integrity, and availability of the affected KIO deployment.
Affected software
- Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects): all versions before v1.9
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade Klemsan KIO to v1.9 or later, which resolves this vulnerability.
- If unable to patch immediately: Restrict network exposure of KIO management/application interfaces — do not expose them directly to the internet, and limit access to trusted internal networks or via VPN/firewall allow-listing until the upgrade can be applied.
- Monitor KIO systems for unexpected code execution or anomalous process activity as an interim detection measure while patching is in progress.

