Insecure SSH Configuration in BSH ELP Modules Exposes Root Access
CVE-2026-56428
8.1HIGH
Key Information:
- Vendor
Bosch
- Vendor
- CVE Published:
- 30 July 2026
What is CVE-2026-56428?
The SSH service within BSH ELP (Electronic Platform) modules is vulnerable due to the presence of an insecure default configuration. Specifically, an unremovable SSH public key has been included in the firmware's authorized_keys file for the root user. This oversight allows attackers possessing the corresponding private key to bypass authentication measures and gain root-level access to the appliance, potentially leading to unauthorized control and exploitation of the affected systems.
Affected Version(s)
BSH ELP (Electronic Platform) Modules 65.0.0 < 65.2.12