CVE Feed

    Dashboard / CVE / CVE-2026-41446

    CVE-2026-41446

    Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device label or documentation containing these values can authenticate to the several endpoints and execute arbitrary commands as root on the device.

    Published:Apr 28, 2026
    Last Modified:Apr 29, 2026
    EPS:Apr 28, 2026
    EPSS Score:0.0007
    CVSS Score:9.8

    Affected Products

    Vendor
    Snapone
    Product
    Wattbox 800
    Vendor
    Snapone
    Product
    Wattbox 820

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High