CVE-2026-35097
KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended characters. This issue was fixed in the patch published in June 2026.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.42%
- CWE
- CWE-521
- Published
- 2026-06-30
- Last modified
- 2026-06-30
Affected products
- KTM System e-BOK
Weakness type
Related vulnerabilities
- CVE-2026-85216 — MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
- CVE-2026-19293 — SMP security request
- CVE-2026-12504 — Loytec LINX firmware: Improper Authentication in PAM configuration
- CVE-2026-56577 — HCL MyCloud affected by Weak Password Policy
- CVE-2026-11493 — Tenda AC15 Samba smb.conf weak password
- CVE-2024-40684 — IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout Mechanism
- CVE-2026-9394 — Besen BS20 EV Charging Station Bluetooth Low Energy weak password
- CVE-2026-41038 — Weak Password Policy Vulnerability in Quantum Networks Router QN-I-470