Description
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
Published: 2026-06-03
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in hard–coded default service account passwords embedded in the firmware image of a range of MBS industrial control devices. An unauthenticated remote attacker can extract or recover the default password from the firmware, thereby gaining unrestricted administrative access to any device running the affected firmware. Once compromised, the attacker can execute arbitrary configuration changes, activate or disable critical control functions, and potentially disrupt or manipulate the entire control network. This weakness is essentially a credential exposure flaw, enabling total device takeover without initial authentication.

Affected Systems

Affected products include MBS Double-A Profibus and Double-A x-link, MBS Double-X CAN, DALI, KNX, LON, M-Bus, Profinet, and x-link, as well as MBS Single-A, Single-X, and all MBS Triple-X device lines that combine KNX, DALI, LON, M-Bus, and Profinet protocols. No specific firmware revisions were identified in the report, so any current revision of these product lines may be vulnerable.

Risk and Exploitability

The CVSS base score of 9.3 indicates a severe risk, reflecting the zero‑trust attack model and complete loss of confidentiality, integrity, and availability of the devices. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high severity and remote exploitability mean that a motivated attacker could mount a successful breach. The attack vector is remote and does not require any privileged interface; it is based on exploiting a firmware design flaw that exposes a default credential.

Generated by OpenCVE AI on June 3, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a vendor‑supplied firmware update that removes or obscures the hard‑coded service account password.
  • If an update is unavailable, change the default service account password on every device or disable the account entirely.
  • Further limit exposure by restricting management‑interface access to trusted IP ranges or VPN connections only.

Generated by OpenCVE AI on June 3, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
Title Hardcoded default Password for Service Account
First Time appeared Mbs
Mbs double A Profibus Firmware
Mbs double A X Link Firmware
Mbs double X Can Firmware
Mbs double X Dali Firmware
Mbs double X Knx Firmware
Mbs double X Lon Firmware
Mbs double X M Bus Firmware
Mbs double X Profinet Firmware
Mbs double X X Link Firmware
Mbs single A Firmware
Mbs single X Firmware
Mbs triple X Knx Dali Firmware
Mbs triple X Knx Lon Firmware
Mbs triple X Knx M Bus Firmware
Mbs triple X Profinet Dali Firmware
Mbs triple X Profinet Knx Firmware
Mbs triple X Profinet Lon Firmware
Mbs triple X Profinet M Bus Firmware
Weaknesses CWE-1393
CPEs cpe:2.3:o:mbs:double_a_profibus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_a_x_link_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_can_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_dali_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_knx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_lon_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_m_bus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_profinet_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_x_link_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:single_a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:single_x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_knx_dali_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_knx_lon_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_knx_m_bus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_dali_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_knx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_lon_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_m_bus_firmware:*:*:*:*:*:*:*:*
Vendors & Products Mbs
Mbs double A Profibus Firmware
Mbs double A X Link Firmware
Mbs double X Can Firmware
Mbs double X Dali Firmware
Mbs double X Knx Firmware
Mbs double X Lon Firmware
Mbs double X M Bus Firmware
Mbs double X Profinet Firmware
Mbs double X X Link Firmware
Mbs single A Firmware
Mbs single X Firmware
Mbs triple X Knx Dali Firmware
Mbs triple X Knx Lon Firmware
Mbs triple X Knx M Bus Firmware
Mbs triple X Profinet Dali Firmware
Mbs triple X Profinet Knx Firmware
Mbs triple X Profinet Lon Firmware
Mbs triple X Profinet M Bus Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mbs Double A Profibus Firmware Double A X Link Firmware Double X Can Firmware Double X Dali Firmware Double X Knx Firmware Double X Lon Firmware Double X M Bus Firmware Double X Profinet Firmware Double X X Link Firmware Single A Firmware Single X Firmware Triple X Knx Dali Firmware Triple X Knx Lon Firmware Triple X Knx M Bus Firmware Triple X Profinet Dali Firmware Triple X Profinet Knx Firmware Triple X Profinet Lon Firmware Triple X Profinet M Bus Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-06-03T12:41:59.999Z

Reserved: 2026-04-01T08:28:27.141Z

Link: CVE-2026-35075

cve-icon Vulnrichment

Updated: 2026-06-03T12:41:02.684Z

cve-icon NVD

Status : Received

Published: 2026-06-03T13:16:19.407

Modified: 2026-06-03T13:16:19.407

Link: CVE-2026-35075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T13:30:26Z

Weaknesses