CVE-2026-22101 PUBLISHED

Sensitive information leak through hidden menu

Assigner: DIVD
Reserved: 06.01.2026 Published: 29.09.2026 Updated: 29.09.2026

The access to the service menu is obfuscated, but possible with only physical access. This menu exposes sensitive information such as serial numbers, MAC addresses, and WiFi network and password.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor EVbee
Product DC-80
Versions Default: unaffected
  • Version unknown is affected

Credits

  • Wilco van Beijnum (ElaadNL) finder
  • Jeroen van der Ham-de Vos (DIVD) analyst

References

Problem Types

  • CWE-200 CWE