CISA advisory: hard-coded credentials in KUKA KR C4 robot controller (CVSS 9.8)
S1 · 27 Jul 2021 · KUKA
Record
| Company | KUKA |
| Industry | Machinery OEM |
| Type(s) | cyber |
| Date | 27 Jul 2021 (day precision) |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | (near-miss / disclosed vulnerability) |
| Scale | KUKA KR C4 controller product line |
| Confidence | high |
| Verified flag | Cited source on file; not independently re-verified |
Summary
CISA published ICSA-21-208-01 detailing a critical hard-coded-credentials flaw in KUKA KR C4 controllers (KSS versions prior to 8.7) that could give an attacker full read/write/delete access to sensitive system folders; no known public exploitation, patch issued.
Primary source
Publisher: CISA ICS-CERT · Retrieved: 2026-09-16
Supporting source rows (1)
| Date | Supporting source row | Publisher | Link |
|---|---|---|---|
| 27 Jul 2021 | CISA advisory: hard-coded credentials in KUKA KR C4 robot controller (CVSS 9.8) | CISA ICS-CERT | CISA ICS-CERT |
KUKA other incidents timeline
Machinery OEM context
cyber context
KUKA industry position
Related incidents
Other KUKA entries
Report a correction
Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs