Impact
An improper physical access control flaw in ShizenBox2 (dev-conf) permits an attacker who can physically reach the device to run bootloader commands without any authentication. If an attacker can execute these commands, they may load custom firmware or manipulate the boot process, potentially gaining full control over the system and compromising data confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Shizen Connect Inc.'s ShizenBox2 device (dev-conf). No specific firmware or hardware version information is disclosed, so all currently deployed models are potentially impacted until a vendor update is released.
Risk and Exploitability
The CVSS score of 7 indicates a high severity rating, but the EPSS score is not available and the issue is not listed in CISA’s KEV catalog. Because the flaw requires physical access, the likelihood of exploitation is limited to environments where an attacker can reach the device. There is no public evidence of an active exploit or a published mitigation from the vendor, so the primary risk remains installation and handling procedures rather than a widespread attack vector.
OpenCVE Enrichment