← Back to overview

A Code Injection vulnerability (CVE-2026-18808) has been identified in Klemsan Electrical Electronics Inc.'s KIO (Klemsan Internet Objects) product. The vulnerability is classified as Improper Control of Generation of Code, allowing attackers to perform code injection attacks. All versions of KIO prior to v1.9 are affected. The issue has been reported via the Turkish cybersecurity authority (siberguvenlik.gov.tr) and published on NVD. Users are advised to upgrade to v1.9 or later to remediate the vulnerability. The KIO product is an industrial IoT-oriented device, making this vulnerability particularly significant for operational technology environments. No additional exploitation details or proof-of-concept references are currently noted in the advisory.

Affected products

  • KIO (Klemsan Internet Objects)

Related CVE's

  • CVE-2026-18808

Categories

  • Critical Infrastructure
  • Mobile & IoT