CVE-2026-22094 PUBLISHED

Weak root password in EVbee DC 80

Assigner: DIVD
Reserved: 06.01.2026 Published: 29.09.2026 Updated: 29.09.2026

The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using the SSH daemon that is exposed to the network.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor EVbee
Product DC 80
Versions Default: unaffected
  • Version unknown is affected

Credits

  • Wilco van Beijnum (ElaadNL) finder
  • Jeroen van der Ham-de Vos (DIVD) analyst

References

Problem Types

  • CWE-1391 CWE