← Database

CVE-2026-73778

HIGH CVSS: 8.1 Published: 2026-09-01 Modified: 2026-09-01

Description

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.

Affected Platforms

Unknown

Weakness Type

Unknown

References