CRITICAL🇵🇱 Wersja polska

CVE-2026-26366

CVSS 9.3v4.0pub. 2026-02-15upd. 2026-02-26

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.

🤖 AI Analysis
How it works

The vulnerability results from the use of default, widely known authentication credentials (CWE-1392), which are not invalidated or changed during the device installation and configuration process. The manufacturer does not enforce mandatory password change after the first server startup. As a result, any attacker with network access to the server's interface can log in using 'user:user' or 'admin:admin' accounts, completely bypassing authentication mechanisms.

Impact

An attacker gains full administrative access to the configuration and control functions of the smart home system, enabling manipulation of settings, takeover of connected devices, and potential violation of user privacy and physical security.

Mitigation & patch

Default passwords for all accounts (particularly 'user' and 'admin') must be immediately changed to strong, unique passwords immediately after installation. Patches available from the manufacturer should be applied according to references, and network access to the server's management interface should be restricted exclusively to trusted hosts (e.g., through firewall or network segmentation).

Who is affected

Jung-Group eNet SMART HOME Server in versions 2.2.1 and 2.3.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Jung Group Enet Smart Home

    APP
    Jung-Group
    2.2.12.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-26367HIGH7.1same product

eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount...

CVE-2026-26368HIGH8.7same product

eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword...

CVE-2026-26369HIGH8.7PL ✓same product

Privilege escalation w eNet SMART HOME Server przez metodę setUserGroup

CVE-2026-26234HIGH8.7same vendor

JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticat...

CVE-2026-26235HIGH8.7same vendor

JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attacke...