CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-26366
Severity
CRITICAL
CVSS
9.8
EPSS
0.65%
Original NVD Description
eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.
Related CVEs
Other vulnerabilities affecting the same vendor(s)