CVE-2026-22094: Weak root password in EVbee DC 80
Published Sep 29, 2026
·Updated
The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using the SSH daemon that is exposed to the network.
Affected Software
1 affected component
EVbee DC-80 firmware
Event History
Sep 29, 2026
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
An attacker needs network access to the device's exposed SSH daemon and the hardcoded root password.
2
What level of access does successful exploitation provide?
Successful SSH login using the hardcoded credentials provides root access to the EVbee DC-80.