Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 0.4%
from disclosure to weapon0 days
Published on NVDAug 20
1st PoCJul 14
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass.
This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Baylan Measuring Instruments Industry and Trade Inc. · Baylan Smart Meter Management Application (BMS)public PoCs found — 1
githubgithub.com/musana/CVE-2026-15706★ 2⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.