CVE-2026-3587: exploitation status and patch state
CVE-2026-3587 · CVSS 10.0 CRITICAL · EPSS 1%
An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.
Is CVE-2026-3587 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.