CVE-2026-35075
Hardcoded default Password for Service Account
In short
A default password is embedded in the firmware of affected devices, allowing anyone who downloads the firmware to discover it and gain full control of the system without needing to log in first.
Technical detail
An attacker can extract the hardcoded service account credentials from publicly available or accessible firmware images, enabling unauthenticated remote access with full privileges. Pre-condition: ability to obtain the firmware; impact: complete device compromise and lateral movement within the network.
Summary generated and translated by AI from the official description.
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
MBS · Double-A ProfibusMBS · Double-A x-linkMBS · Double-X CANMBS · Double-X DALIMBS · Double-X KNXMBS · Double-X LONMBS · Double-X M-BusMBS · Double-X PROFINETMBS · Double-X x-linkMBS · Single-AMBS · Single-XMBS · Triple-X KNX+DALIMBS · Triple-X KNX+LONMBS · Triple-X KNX+M-BusMBS · Triple-X PROFINET+DALIMBS · Triple-X PROFINET+KNXMBS · Triple-X PROFINET+LONMBS · Triple-X PROFINET+M-BusWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →