Impact
The Code 27 Companion Hub has a protection mechanism failure that permits anyone with physical access to perform a factory reset that completely disables the device’s kiosk restrictions. The flaw is an instance of CWE‑288, where the system fails to properly identify authorized actions, allowing a reset that removes all enforced kiosk configurations and thereby enabling unrestricted use of the hub. Because the reset bypasses all security limits, an attacker can operate the device outside its intended public‑use constraints.
Affected Systems
The affected device is the Code 27 Companion Hub. No specific firmware or model versions are listed in the available data, so all installations that include the standard factory‑reset function should be considered at risk.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity, and the EPSS score of less than 1 % suggests a low overall exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog. The primary attack vector requires physical access to the hub; once a reset is executed, kiosk restrictions are lost and the device can be used without limits. In environments with strict physical security the risk remains limited, but sites that lack secure controls around the hub are vulnerable to unauthorized use.
OpenCVE Enrichment