RobotRisk Autonomous Systems Incident & Risk Register
RobotRiskKUKA › 27 Jul 2021

CISA advisory: hard-coded credentials in KUKA KR C4 robot controller (CVSS 9.8)

S1 · 27 Jul 2021 · KUKA

Record

CompanyKUKA
IndustryMachinery OEM
Type(s)cyber
Date27 Jul 2021 (day precision)
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
Severity (near-miss / disclosed vulnerability)
ScaleKUKA KR C4 controller product line
Confidencehigh
Verified flagCited source on file; not independently re-verified

Summary

CISA published ICSA-21-208-01 detailing a critical hard-coded-credentials flaw in KUKA KR C4 controllers (KSS versions prior to 8.7) that could give an attacker full read/write/delete access to sensitive system folders; no known public exploitation, patch issued.

Primary source

CISA ICS-CERT

Publisher: CISA ICS-CERT · Retrieved: 2026-09-16

Supporting source rows (1)
DateSupporting source rowPublisherLink
27 Jul 2021 CISA advisory: hard-coded credentials in KUKA KR C4 robot controller (CVSS 9.8) CISA ICS-CERT CISA ICS-CERT

KUKA other incidents timeline

Machinery OEM context

cyber context

KUKA industry position

Related incidents

Other KUKA entries

Report a correction

Open a prefilled GitHub issue

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs