Description
A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset
Published: 2026-07-08
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Code 27 Companion Hub has a protection mechanism failure that permits anyone with physical access to perform a factory reset that completely disables the device’s kiosk restrictions. The flaw is an instance of CWE‑288, where the system fails to properly identify authorized actions, allowing a reset that removes all enforced kiosk configurations and thereby enabling unrestricted use of the hub. Because the reset bypasses all security limits, an attacker can operate the device outside its intended public‑use constraints.

Affected Systems

The affected device is the Code 27 Companion Hub. No specific firmware or model versions are listed in the available data, so all installations that include the standard factory‑reset function should be considered at risk.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity, and the EPSS score of less than 1 % suggests a low overall exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog. The primary attack vector requires physical access to the hub; once a reset is executed, kiosk restrictions are lost and the device can be used without limits. In environments with strict physical security the risk remains limited, but sites that lack secure controls around the hub are vulnerable to unauthorized use.

Generated by OpenCVE AI on July 26, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enforce physical security for the hub by placing it in lockable enclosures and restricting access to authorized personnel.
  • Apply any available Code 27 firmware update that locks the factory‑reset process or requires authentication before execution.
  • If a firmware update is unavailable, disable the reset function through device configuration or by physically blocking the reset button.

Generated by OpenCVE AI on July 26, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Factory Reset Enables Kiosk Restriction Bypass with Physical Access

Thu, 23 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Kiosk Restriction Bypass via Factory Reset on Code 27 Companion Hub

Tue, 21 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Kiosk Restriction Bypass via Factory Reset on Code 27 Companion Hub

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Factory Reset Bypass Disables Kiosk Protection in Code 27 Companion Hub

Tue, 14 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Factory Reset Bypass Disables Kiosk Protection in Code 27 Companion Hub

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Factory Reset Bypass in Code 27 Companion Hub Allows Physical Attacker to Remove Kiosk Restrictions

Sat, 11 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Factory Reset Bypass in Code 27 Companion Hub Allows Physical Attacker to Remove Kiosk Restrictions

Fri, 10 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Factory Reset Bypass via Physical Access in Code 27 Companion Hub

Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Factory Reset Bypass via Physical Access in Code 27 Companion Hub

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-09T14:53:24.816Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36028

cve-icon Vulnrichment

Updated: 2026-07-09T14:53:10.939Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T18:45:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel