CVE-2026-28745

Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.

Credits

Gabrianna (Ria) Milloway of Idaho National Laboratory reported this vulnerability to CISA.

References