The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-30 14:16
Updated : 2026-07-30 16:45
NVD link : CVE-2026-56428
Mitre link : CVE-2026-56428
CVE.ORG link : CVE-2026-56428
JSON object : View
Products Affected
No product.
CWE
CWE-286
Incorrect User Management
