Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Güralp Systems Ltd

Güralp Systems Ltd Vendor Cyber Rating & Cyber Score

guralp.com

We manufacture force-feedback, broadband seismometers, accelerometers and data acquisition systems for a range of research and industrial applications. Installed in networks around the globe, our customers use our instruments to measure natural earthquakes and volcanic eruptions, as well as man-made vibrations and tremors such as those resulting from nuclear tests, energy production or the construction of major infrastructure. We are constantly developing new ways of engineering this precision technology into smaller and more advanced casings that can be deployed in the harshest of environments, from the Antarctic ice sheet; to bore-holes hundreds of metres deep; to the world’s most active volcanoes and deepest ocean trenches. A UK


GSL A.I CyberSecurity Scoring

GSL
Company Information
Website:http://www.guralp.com
Employees number:72
Number of followers:2,213
NAICS:30
Industry Type:Manufacturing
Homepage:guralp.com
GSL Risk Score (AI oriented)
Between 750 and 799
logo
GSLManufacturing
Updated:
06/03/2026
750/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
GSL Global Score (TPRM)
xxxx
logo
GSLManufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

GSL
GSLFair
Current Score
750Baa (FAIR)
01000
1 incidents
-11 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
760Before Incident
Vulnerability
13 Jan 2026GSL
Güralp Systems, Rockwell Automation and YoSmart: CISA issues multiple ICS advisories, details DoS vulnerability risk in Rockwell devices used in critical manufacturing

CISA Publishes Advisories on Vulnerabilities in Rockwell Automation and YoSmart Products

749After Incident
CRITICAL-11
GURROCYOS1768400893
CISA Issues Critical ICS Advisories for Rockwell Automation and YoSmart Vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released three new advisories and updated an existing one on Tuesday, highlighting significant vulnerabilities in industrial control systems (ICS) from Rockwell Automation and YoSmart. The advisories address risks in critical manufacturing and global communications sectors, with potential impacts ranging from denial-of-service (DoS) conditions to unauthorized device control. ### Rockwell Automation Vulnerabilities 1. CVE-2025-9368 (CVSS 7.5) - Affects Rockwell Automation 432ES-IG3 Series A devices, specifically the GuardLink EtherNet/IP Interface. - The flaw stems from uncontrolled resource allocation, allowing attackers to trigger a DoS condition requiring a manual power cycle to restore functionality. - Mitigation: Users should upgrade to V2.001.9 or later; those unable to update should follow Rockwell’s security best practices. 2. CVE-2025-12807 (CVSS 8.8) - Impacts FactoryTalk DataMosaix Private Cloud (versions 7.11, 8.00, and 8.01). - The vulnerability involves SQL injection, enabling low-privilege users to execute unauthorized database operations via exposed API endpoints. - Mitigation: Update to Version 8.01.02 or later. ### YoSmart YoLink Smart Hub Vulnerabilities Multiple flaws were identified in the YoSmart YoLink ecosystem, affecting the Smart Hub, server, and mobile application (CVE-2025-59448, CVE-2025-59449, CVE-2025-59451, CVE-2025-59452), with a CVSS score of 5.8. - Exploitation Risks: - Remote device control of other users’ smart home devices. - Session hijacking and sensitive data interception due to weak authorization controls and predictable device IDs. - Cleartext transmission of data via unencrypted MQTT, exposing communications to interception or tampering. - Long-lived session tokens in the mobile app, increasing the risk of unauthorized access. - Technical Details: - The YoLink MQTT broker (through 2025-10-02) lacks sufficient authorization checks, allowing cross-account attacks if device IDs are obtained. - Device IDs are predictable, enabling attackers to gain control over any YoLink user’s devices. - API endpoints use MD5 hashing of non-secret data (e.g., MAC addresses), further weakening security. ### CISA’s Recommendations While no active exploitation has been reported, CISA advises organizations to: - Minimize network exposure for ICS devices, ensuring they are not internet-accessible. - Isolate control systems behind firewalls and separate them from business networks. - Use secure remote access methods, such as updated VPNs, when necessary. - Conduct risk assessments before deploying defensive measures. The advisories underscore ongoing risks in ICS environments, particularly in critical infrastructure sectors. Organizations are urged to apply patches and follow CISA’s Defense-in-Depth Strategies for proactive cybersecurity.
INCIDENT DETAILS -
TYPE
Denial-of-ServiceSQL InjectionUnauthorized AccessSession Hijacking
IMPACT
Sensitive database operationsPersonally identifiable informationSession tokensRockwell Automation 432ES-IG3 Series ARockwell Automation FactoryTalk DataMosaix Private CloudYoSmart YoLink Smart HubYoLink Mobile ApplicationDowntime: Manual power cycle required for recovery (Rockwell Automation 432ES-IG3 Series A)Denial-of-service conditionUnauthorized control of smart home devicesIdentity Theft Risk: High (due to PII exposure)
DATA BREACH
Database operationsSession tokensDevice identifiersSensitivity Of Data: High (PII, device control access)Data Exfiltration: Possible (via MQTT traffic interception)Data Encryption: Lacking (cleartext MQTT transmission)Personally Identifiable Information: Yes
DECEMBER 2025
760Before Incident
NOVEMBER 2025
760Before Incident
OCTOBER 2025
760Before Incident
SEPTEMBER 2025
760Before Incident
AUGUST 2025
760Before Incident
JULY 2025
760Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for GSL ?
?
What was GSL's A.I Rankiteo Cyber Score in May 2026 ?
?
What was GSL's A.I Rankiteo Cyber Score in April 2026 ?
?
What was GSL's A.I Rankiteo Cyber Score in March 2026 ?
?
What was GSL's A.I Rankiteo Cyber Score in February 2026 ?
?
What was GSL's A.I Rankiteo Cyber Score in January 2026 ?
?
What was GSL's A.I Rankiteo Cyber Score in December 2025 ?
?
What was GSL's A.I Rankiteo Cyber Score in November 2025 ?
?
What was GSL's A.I Rankiteo Cyber Score in October 2025 ?
?
What was GSL's A.I Rankiteo Cyber Score in September 2025 ?
?
What was GSL's A.I Rankiteo Cyber Score in August 2025 ?
?
What was GSL's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on GSL's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with GSL ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view GSL's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?