CVE-2026-90498
A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.28%
- CWE
- CWE-1392
- Published
- 2026-09-13
- Last modified
- 2026-09-15
Affected products
- lenve vhr
Weakness type
Related vulnerabilities
- CVE-2024-12856 — Four-Faith Industrial Router adjust_sys_time OS Command Injection
- CVE-2025-8731 — TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials
- CVE-2025-55051 — CWE-1392: Use of Default Credentials
- CVE-2025-12218 — Weak Default Credentials
- CVE-2023-3703 — Proscend Advice ICR Series routers fw version 1.76
- CVE-2023-30801 — qBittorrent Web UI Default Credentials Lead to RCE
- CVE-2023-30603 — Hitron Technologies Inc. CODA-5310 - Using default credentials
- CVE-2023-49621 — A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system sta