Weak Hardcoded Password in Firmware of EVbee DC-80 Device
CVE-2026-22094

9.3CRITICAL

Key Information:

Vendor

Evbee

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-22094?

The firmware for the EVbee DC-80 presents a significant security risk due to its use of a weak hardcoded root password. This vulnerability allows attackers to gain unauthorized access by logging in as root through the SSH daemon, which is exposed to the network. Such exploitation can lead to unauthorized actions and potential compromise of the device's security, emphasizing the need for immediate attention to secure firmware practices.

Affected Version(s)

DC 80 unknown

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wilco van Beijnum (ElaadNL)
Jeroen van der Ham-de Vos (DIVD)
.