CVE-2026-22101: Sensitive information leak through hidden menu
Published Sep 29, 2026
·Updated
The access to the service menu is obfuscated, but possible with only physical access. This menu exposes sensitive information such as serial numbers, MAC addresses, and WiFi network and password.
Event History
Sep 29, 2026
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Devices that can be physically accessed are exposed because the service menu can be reached despite being obfuscated. An attacker with physical access could view serial numbers, MAC addresses, and WiFi network credentials.
2
What level of access does an attacker need?
Only physical access is required. The available information does not indicate that prior authentication or network access is needed.
3
What sensitive data could be disclosed?
The service menu exposes serial numbers, MAC addresses, WiFi network information, and the WiFi password.