OT Security: Critical Flaws in Cisco, ASUS, TP-Link & Satel Gear

OT Security Digest: Flaws in Cisco, ASUS, TP-Link, Satel Devices

MEDIUM
October 11, 2026
5m read
VulnerabilityIndustrial Control SystemsPatch Management

Related Entities

Organizations

Cisco ASUS TP-Link SatelINCIBE-CERT

Products & Tech

Cisco Nexus 3000Cisco Nexus 9000TP-Link Tapo C325WB V2Satel SenNet Datalogger Serie 200

CVE Identifiers

CVE-2026-76465
CRITICAL
CVSS:9.8
CVE-2026-14911
CRITICAL
CVSS:9.3
CVE-2026-19386
CRITICAL
CVSS:9.3
CVE-2026-105672
HIGH
CVE-2026-105673
HIGH
CVE-2026-105674
HIGH
CVE-2026-5703
HIGH
CVSS:7.1

Full Report

Executive Summary

A roundup of Operational Technology (OT) security advisories from October 10, 2026, reveals multiple critical and high-severity vulnerabilities across a range of widely used networking and IoT devices. Cisco addressed a critical (9.8 CVSS) remote code execution (RCE) vulnerability, CVE-2026-76465, in its Nexus 3000 and 9000 series switches. ASUS released firmware updates for two critical (9.3 CVSS) code execution flaws in its routers. Additionally, TP-Link patched high-severity bugs in its Tapo security cameras, and a path traversal flaw was disclosed in Satel SenNet industrial dataloggers. These disclosures underscore the persistent security challenges in both enterprise and industrial connected devices, requiring prompt attention from asset owners.


Vulnerability Details

Cisco Nexus Switches - CVE-2026-76465

  • Vulnerability: Remote Code Execution
  • CVSS Score: 9.8 (Critical)
  • Affected Products: Cisco Nexus 3000 and 9000 Series Switches
  • Description: A flaw in the MPLS OAM feature could allow an unauthenticated, remote attacker to execute code with root privileges or cause a denial of service by sending a crafted MPLS echo request. The feature is not enabled by default, which limits the number of vulnerable devices.

ASUS Routers - CVE-2026-14911 & CVE-2026-19386

  • Vulnerability: Arbitrary Code Execution
  • CVSS Score: 9.3 (Critical)
  • Affected Products: ASUS routers with firmware series 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102.
  • Description: The flaws allow for code execution via a crafted configuration file upload or by tricking a user into clicking a malicious link.

TP-Link Tapo Cameras - CVE-2026-105672, etc.

  • Vulnerability: API Authentication Bypass, DoS, Key Prediction
  • Severity: High
  • Affected Products: TP-Link Tapo C325WB V2 cameras (firmware prior to V2_1.3.3 Build 260914)
  • Description: A set of flaws allows an attacker on the adjacent network to bypass authentication, disrupt video streams, and predict local stream keys.

Satel SenNet Datalogger - CVE-2026-5703

  • Vulnerability: Authenticated Path Traversal
  • CVSS v4.0 Score: 7.1 (High)
  • Affected Products: Satel SenNet Datalogger Serie 200 (V7.0m-1.53h)
  • Description: An authenticated user can read arbitrary files and list directories on the device, potentially exposing sensitive configuration data or credentials used in industrial energy monitoring systems.

Exploitation Status

At the time of publication, Cisco reported no public exploitation of CVE-2026-76465. The exploitation status for the other vulnerabilities was not specified in the source articles, but patches are available for all listed flaws.

Impact Assessment

These vulnerabilities pose significant risks to both enterprise and industrial networks.

  • The Cisco Nexus flaw is particularly severe, as these switches are often core components of data center and enterprise networks. A root-level compromise could lead to a complete network takeover.
  • The ASUS router vulnerabilities expose many small business and home networks to compromise, which can then be absorbed into botnets.
  • The TP-Link camera flaws could allow an attacker to spy on users or disable security monitoring, while the Satel datalogger vulnerability could expose sensitive information about industrial processes and energy consumption, useful for reconnaissance in a more targeted attack.

Cyber Observables — Hunting Hints

The following patterns may help identify vulnerable or compromised systems:

Type
network_traffic_pattern
Value
Inbound MPLS echo requests (MPLS OAM) to Cisco Nexus switches from untrusted sources.
Description
Potential attempt to exploit CVE-2026-76465.
Type
log_source
Value
ASUS router logs
Description
Look for configuration file uploads from unknown sources or suspicious script execution events.
Type
network_traffic_pattern
Value
Unexpected API calls to TP-Link Tapo cameras from devices on the local network.
Description
Possible attempt to exploit the authentication bypass.

Detection Methods

  • Asset Inventory & Vulnerability Scanning: The first step is to identify if these devices exist in your environment and if they are running vulnerable software versions. Use network scanners and asset management tools to find Cisco Nexus switches, ASUS routers, TP-Link cameras, and Satel dataloggers.
  • Log Analysis: For the Cisco flaw, monitor for logs related to the MPLS OAM feature. For the Satel flaw, monitor for unusual file access patterns from authenticated users.

Remediation Steps

  1. Prioritize and Patch: Review your asset inventory to identify affected devices. Prioritize patching based on criticality and exposure. The Cisco Nexus flaw should be a top priority for data centers where MPLS is in use. Home and small business users of affected ASUS routers should update their firmware immediately.
  2. Disable Unused Features: For the Cisco Nexus vulnerability, the MPLS OAM feature is disabled by default. If you are not using this feature, ensure it remains disabled. This is a powerful mitigation step.
  3. Network Segmentation: Isolate IoT and OT devices like cameras and dataloggers on separate network segments with restricted access to and from the corporate network. This contains the impact of a potential compromise. This aligns with D3FEND Network Isolation.

Timeline of Events

1
October 11, 2026
This article was published

MITRE ATT&CK Mitigations

Apply the firmware and software updates provided by the respective vendors to remediate the vulnerabilities.

For the Cisco Nexus flaw, disable the MPLS OAM feature if it is not required for business operations.

Isolate IoT and OT devices like cameras and dataloggers on their own network segments to limit the impact of a compromise.

D3FEND Defensive Countermeasures

For all vulnerabilities listed in this digest, the primary and most effective remediation is to apply the security updates provided by the vendors. Organizations should use their asset inventory to identify all affected Cisco Nexus switches, ASUS routers, TP-Link cameras, and Satel dataloggers. A risk-based patching priority should be established. The critical RCE flaw in Cisco Nexus switches (CVE-2026-76465) should be prioritized for any data center or enterprise network where the MPLS OAM feature is enabled. Due to the critical nature of the ASUS router flaws, all users should update their firmware immediately to prevent device compromise.

A powerful mitigation for the Cisco Nexus vulnerability (CVE-2026-76465) is to disable the feature that contains the flaw. The MPLS OAM feature is disabled by default. Network administrators should verify its status by running show feature | i mpls_oam on their switches. If the feature is enabled but not essential for current operations, it should be disabled immediately using the no feature mpls oam command. This action completely removes the attack surface for this specific vulnerability without requiring an immediate patch cycle, serving as an excellent compensating control. This principle of disabling unused features should be applied across all network devices to minimize the overall attack surface.

Sources & References

Daily OT Security News: October 10, 2026
Security Boulevard (securityboulevard.com) •October 10, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

OT SecurityVulnerabilityCiscoASUSTP-LinkSatelRCEPatch Management

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.