CVE-2026-24789
Severity CVSS v4.0:
CRITICAL
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
11/02/2026
Last modified:
11/02/2026
Description
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL



