CVE-2026-26366

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
15/02/2026
Last modified:
15/02/2026

Description

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.