Default Credentials Vulnerability in eNet SMART HOME Server by JUNG
CVE-2026-26366

9.3CRITICAL

Key Information:

Vendor

Jung

Vendor
CVE Published:
15 February 2026

What is CVE-2026-26366?

The eNet SMART HOME server versions 2.2.1 and 2.3.1 are shipped with default login credentials that remain unchanged post-installation. This flaw allows unauthorized users to gain full administrative access to smart home configurations, posing significant security risks as attackers can exploit this vulnerability to manipulate sensitive smart home functions without any authentication.

Affected Version(s)

eNet SMART HOME server 2.3.1 (46841)

eNet SMART HOME server 2.2.1 (46056)

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LiquidWorm as Gjoko Krstic of Zero Science Lab
.