Weak Hardcoded Password in Firmware of EVbee DC-80 Device
CVE-2026-22094
9.3CRITICAL
What is CVE-2026-22094?
The firmware for the EVbee DC-80 presents a significant security risk due to its use of a weak hardcoded root password. This vulnerability allows attackers to gain unauthorized access by logging in as root through the SSH daemon, which is exposed to the network. Such exploitation can lead to unauthorized actions and potential compromise of the device's security, emphasizing the need for immediate attention to secure firmware practices.
Affected Version(s)
DC 80 unknown
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Wilco van Beijnum (ElaadNL)
Jeroen van der Ham-de Vos (DIVD)
