CVE-2026-26366

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jung-group:enet_smart_home:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:jung-group:enet_smart_home:2.3.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-15 16:15

Updated : 2026-02-26 22:44


NVD link : CVE-2026-26366

Mitre link : CVE-2026-26366

CVE.ORG link : CVE-2026-26366


JSON object : View

Products Affected

jung-group

  • enet_smart_home
CWE
CWE-1392

Use of Default Credentials