criticalZero-Day

Gigatech PDV5701 WebSocket Service Authentication Bypass

First seen Sep 22, 2026 · Updated Sep 22, 2026 · CVSS 10

iotauthentication-bypasswebsocketremote-exploitunpatchedpublic-exploit

A critical unauthenticated access vulnerability has been publicly disclosed in Gigatech PDV5701 devices running firmware 1.0.31_240305_112640. The flaw resides in the WebSocket Service handling of /index.html and allows remote attackers to bypass authentication entirely, with a maximum CVSS score of 10.0. The vendor has not acknowledged or responded to the disclosure, and a public exploit is already available, leaving affected devices exposed with no official patch.

Technical Analysis

CVE-2026-94493 stems from missing authentication checks in the WebSocket Service component when processing requests to /index.html on Gigatech PDV5701 devices. This allows unauthenticated remote attackers to interact with privileged device functionality over the WebSocket interface, likely enabling full device takeover, data exfiltration, or use as a pivot point into internal networks. The vulnerability requires no user interaction and no credentials, and public exploit code is circulating, significantly increasing the likelihood of mass exploitation via internet scanning (e.g., Shodan/Censys). No vendor patch or mitigation guidance exists, as Gigatech has not responded to disclosure attempts, making this an effectively unpatched zero-day in active exploitation risk. Organizations deploying AI agents that interact with IoT/edge device APIs or that operate on networks containing these devices face indirect risk, as a compromised PDV5701 could serve as a foothold for lateral movement toward systems hosting agent credentials, RAG data stores, or orchestration infrastructure.

Affected Systems

Gigatech PDV5701 devices running firmware version 1.0.31_240305_112640, specifically the WebSocket Service component processing /index.html requests

Indicators of Compromise

  • No specific IOCs published at this time; monitor for anomalous WebSocket connections to /index.html on Gigatech PDV5701 devices from unrecognized external IP addresses

Remediation Steps

  1. 1

    Network Isolation

    Immediately isolate Gigatech PDV5701 devices from untrusted networks and the public internet; restrict access to trusted internal segments only via firewall rules or VLAN segmentation.

  2. 2

    Disable WebSocket Service

    If feasible, disable the WebSocket Service component on affected devices until a vendor patch is available.

  3. 3

    Monitor for Exploitation

    Deploy network intrusion detection rules to flag unauthenticated WebSocket requests to /index.html and review logs for signs of prior compromise.

  4. 4

    Vendor Escalation

    Escalate to Gigatech through alternate channels (distributors, regional support) since direct vendor disclosure attempts have failed; track for future firmware updates.

  5. 5

    Compensating Controls

    Deploy a reverse proxy or WAF in front of the device to enforce authentication and filter malicious WebSocket traffic as a temporary mitigation.

CVE / Advisory IDs

CVE-2026-94493

Industries Most Exposed

RetailHospitalityPoint-of-Sale/Payment SystemsCritical InfrastructureManufacturing

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.