OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-22094

CRITICAL · CVSS 9.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The firmware for the EVbee DC-80 contains a hardcoded root password, enabling attackers to gain unauthorized root access via the exposed SSH daemon. This critical vulnerability poses a significant risk to network security, as it allows for complete control over the device. Organizations utilizing this product should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-22094
Severity
CRITICAL
CVSS
9.3
EPSS
0.24%

Original NVD Description

The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using the SSH daemon that is exposed to the network.