CVE Vulnerabilities

CVE-2026-26366

Use of Default Credentials

Published: Feb 15, 2026 | Modified: Feb 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.

Weakness

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Affected Software

NameVendorStart VersionEnd Version
Enet_smart_homeJung-group2.2.1 (including)2.2.1 (including)
Enet_smart_homeJung-group2.3.1 (including)2.3.1 (including)

Potential Mitigations

References