CVE-2026-41446: WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints

Published Apr 28, 2026
·
Updated

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device label or documentation containing these values can authenticate to the several endpoints and execute arbitrary commands as root on the device.

Affected Software

2 affected components
Snap One WattBox 800 Series<2.10.0.0
Snap One WattBox 820 Series<2.10.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snap One WattBox 800 and 820 series to a version that resolves this vulnerability.

    Fixed in 2.10.0.0
  2. Compensating control

    Restrict network access to the undisclosed diagnostic HTTP endpoints on Snap One WattBox 800/820 devices so they are not reachable from unauthorized networks; only allow access from trusted management sources.

  3. Operational

    Reduce exposure of the device MAC address and service tag printed in plaintext on the physical device label, since they are used for authentication to the diagnostic HTTP endpoints (e.g., cover/obscure the label in environments where physical access could be obtained).

Event History

Apr 28, 2026
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-41446?

CVE-2026-41446 is considered to have a high severity due to the potential for remote code execution.

2

How do I fix CVE-2026-41446?

To remediate CVE-2026-41446, upgrade the firmware of your Snap One WattBox 800 or 820 Series devices to version 2.10.0.0 or later.

3

What systems are affected by CVE-2026-41446?

CVE-2026-41446 affects Snap One WattBox 800 and 820 Series devices running firmware versions prior to 2.10.0.0.

4

What kind of exploit is associated with CVE-2026-41446?

CVE-2026-41446 involves remote code execution through undisclosed diagnostic HTTP endpoints.

5

Is authentication necessary for exploiting CVE-2026-41446?

No, CVE-2026-41446 requires only the device MAC address and service tag for authentication, making it easier for attackers to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203