CVE-2026-7251
Severity CVSS v4.0:
CRITICAL
Type:
CWE-259
Use of Hard-coded Password
Publication date:
26/05/2026
Last modified:
04/06/2026
Description
Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL



