TL;DR
SICK InspectorP6xx machine-vision sensors have a critical remote-access flaw. Tracked as CVE-2026-11841, it scores a CVSS of 9.4. An unauthenticated attacker on the network can reach internal files and risk full device compromise.
- CVE: CVE-2026-11841
- CVSS: 9.4 (Critical · CVSSv3)
- Product: SICK AG InspectorP61x
- Affected: < 5.4.0, all versions
- Impact: CVE-2026-11841
- Status: No confirmed exploitation yet
- Patched in: 5.4.0
- EPSS: 0.5% (30-day)
- Action: Update to 5.4.0 now
Why it matters
SICK InspectorP6xx cameras run on factory and automation networks. They inspect parts and guide machines on production lines. Therefore a break-in can disrupt output or corrupt device settings. The flaw needs no login and no user interaction. As a result, any exposed sensor is an easy target.
How the attack works
The problem sits in the SOPAS FileSystemAccess method. It exposes internal virtual filesystem paths without proper access checks. According to SICK, an attacker can “query and modify internal storage locations, configuration files, and system-related application directories.” That access could enable denial of service, configuration tampering, or data theft. SICK warns it “could facilitate further attacks or compromise of the device.” For safety, this report omits any exploit details.
Affected versions
The SICK InspectorP6xx family is widely affected. InspectorP61x and P62x are affected on firmware below 5.4.0. InspectorP63x, P64x, and P65x are affected on all firmware versions. SICK reports no known in-the-wild exploitation or public proof-of-concept.
Patch and mitigation
Update InspectorP61x and P62x to firmware 5.4.0 without delay. For the P63x, P64x, and P65x, no firmware fix exists, so mitigation is the only option. Restrict device access to trusted systems and minimize network exposure. See the full SICK PSIRT advisory for the affected part numbers.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.