CVE-2026-35075
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.47%
- CWE
- CWE-1393
- Published
- 2026-06-03
- Last modified
- 2026-07-03
Affected products
- MBS Single-A
- MBS Double-A Profibus
- MBS Double-A x-link
- MBS Single-X
- MBS Double-X CAN
- MBS Double-X DALI
- MBS Double-X KNX
- MBS Double-X LON
Weakness type
Related vulnerabilities
- CVE-2026-69657 — XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the...
- CVE-2026-82698 — sambitraj Student-Management-System aca.sql default password
- CVE-2026-19851 — Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5
- CVE-2026-5269 — Navigator NCS and MCP System Accounts with Default Passwords
- CVE-2026-54445 — Vantage6: Set admin user and password from environment or configuration
- CVE-2026-8672 — Default credentials for internal DB
- CVE-2026-33784 — JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access
- CVE-2025-14917 — IBM WebSphere Application Server Liberty could provide weaker than expected security