CVE-2026-80253: Medium severity ShizenBox2 (dev-conf) vulnerability
Published Sep 3, 2026
·Updated
An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands without authentication.
Affected Software
1 affected component
ShizenBox2 (dev-conf)
Event History
Sep 3, 2026
CVE Published
via MITRE·08:54 AM
Data Sourced
via MITRE·08:54 AM
DescriptionSeverity
Frequently Asked Questions
1
Who is exposed to exploitation?
Systems running ShizenBox2 (dev-conf) are exposed if an attacker can obtain physical access to the product. Remote-only attackers are not described as able to exploit this issue.
2
What does an attacker need to exploit the issue?
The attacker needs physical access to the product. No authentication is required to execute bootloader commands once that access is obtained.
3
What is the potential impact after exploitation?
An attacker may execute bootloader commands without authentication. The reported impact includes high confidentiality, integrity, and availability effects.