PT-2026-8252 · Unknown · Enet Smart Home Server

Gjoko Krstic

·

Publicado

2026-02-15

·

Atualizado

2026-02-28

·

CVE-2026-26368

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions eNet SMART HOME server versions 2.2.1 and 2.3.1
Description The software contains a missing authorization flaw in the resetUserPassword JSON-RPC method. An authenticated, low-privileged user (UG USER) can reset the passwords of any account, including those with UG ADMIN and UG SUPER ADMIN privileges, without knowing the current password. This is achieved by sending a specially crafted JSON-RPC request to the /jsonrpc/management API endpoint. Successful exploitation allows an attacker to overwrite existing credentials, leading to account takeover and full administrative access with persistent privilege escalation.
Recommendations Update eNet SMART HOME server to a version beyond 2.3.1.

Exploit

Correção

LPE

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26368

Produtos afetados

Enet Smart Home Server