Label Leak: Hardcoded Credentials in Snap One WattBox Devices Open Door to Root Access
ID: ef9d6712-6194-5855-9f8d-17ba965a89ce
STIX ID: report--ef9d6712-6194-5855-9f8d-17ba965a89ce
Feed Name: securityonline.info
Threat Score
A critical vulnerability (CVE-2026-41446, CVSS 9.2) in Snap One WattBox 800/820 series lets attackers who obtain the device MAC address and Service Tag—printed on the device label or available from photos—authenticate to undisclosed diagnostic HTTP endpoints and execute commands as root; Snap One released firmware 2.10.0.0 containing security patches to address this issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
