CVE-2026-26366

Publication date

2026-02-15 15:29:53

Family

VulnCheck

State

PUBLISHED

Description

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.