CISA alerts to critical ASE2000 V2 test set vulnerabilities
Owners of ASE2000 V2 units version 2.25-2.37 must address CVE-2018-1285 and CVE-2026-18717 as of August 27 2026.

The Cybersecurity and Infrastructure Security Agency (CISA) released a notice on August 27, 2026 identifying two high-severity vulnerabilities in Applied Systems Engineering ASE2000 V2 Communications Test Set. The notice applies to ASE2000 units with firmware versions greater than or equal to 2.25 and less than or equal to 2.37.
CVE-2018-1285 stems from an Apache log4net flaw that fails to disable XML external entities when parsing configuration files, creating an XXE attack vector. CVE-2026-18717 is an improper certificate validation issue that could let an attacker impersonate a trusted peer, complete a TLS handshake, and read or modify protected communications. Both vulnerabilities carry a CVSS v3 score of 9.8.
The affected equipment is deployed worldwide and supports critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Water and Wastewater. The notice lists Enoch Wang as the reporter of the vulnerabilities.
CISA recommends that users minimize network exposure of control system devices, place them behind firewalls, and employ VPNs for remote access while keeping VPN software current. Organizations should conduct impact analyses and risk assessments before implementing defensive measures and follow established procedures for reporting suspicious activity to CISA. Additional mitigation guidance is available on the agency's Industrial Control Systems webpage.
The notice, marked as Revision 1, does not indicate any known public exploitation of the vulnerabilities at the time of publication.
Further reading


