CVE-2026-26049

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
20/02/2026
Last modified:
15/04/2026

Description

The web management interface of the device renders the passwords in a <br /> plaintext input field. The current password is directly visible to <br /> anyone with access to the UI, potentially exposing administrator <br /> credentials to unauthorized observation via shoulder surfing, <br /> screenshots, or browser form caching.