Back to all lessons
Awareness Lessons
6 months ago

Critical Vulnerability in Obsolete Industrial Controllers Exposes Critical Infrastructure

Contemporary Controls BASC 20T programmable logic controllers contain a critical vulnerability (CVE-2025-13926) that allows unauthenticated remote attackers to execute arbitrary commands by forging network packets. The flaw stems from the system's reliance on untrusted network inputs, enabling attackers to enumerate, reconfigure, delete, and transfer files without authentication. While the vendor has marked the product as obsolete, many organizations continue using these controllers in critical infrastructure, creating significant security risks. This incident highlights the dangerous combination of legacy industrial systems, inadequate input validation, and insufficient network protections.

Tactical Insight

Immediate actions

  • Identify and inventory all BASC 20T controllers in your environment immediately
  • Isolate affected controllers from untrusted networks using firewalls or air-gapping
  • Plan replacement of obsolete controllers with supported alternatives

Long-term improvements

  • Establish policies to phase out end-of-life industrial control systems
  • Implement network segmentation to isolate industrial control systems from corporate networks
  • Deploy industrial firewalls with deep packet inspection for OT environments

Detection measures

  • Monitor network traffic to industrial controllers for suspicious command patterns
  • Enable logging on network devices protecting industrial control systems