CVE-2026-26366Disclosure(jung-group / enet_smart_home)

MEDIUMCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch jung-group enet_smart_home systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1392

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enet_smart_home

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 5 mentions (2026-02-16); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
enet_smart_home

2 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-02-15: 2Mentions · 2026-02-16: 5Mentions · 2026-02-20: 1PoC Mentioned / Linked · 2026-02-16: 2Exploit Tool / Code · 2026-02-16: 2Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-15: 2Technical Details · 2026-02-16: 3Technical Details · 2026-02-20: 102-1502-1602-20
Signal classification3 categories
Disclosure
562.5%
PoC
225.0%
Patch
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-152
Disclosure2
2026-02-165
Disclosure2Patch1PoC2
2026-02-201
Disclosure1
Full discourse8 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26366 Default Credentials Vulnerability in eNet SMART HOME Server Versi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26366 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    An alert post about CVE-2026-26366 highlights a default credentials vulnerability in eNet SMART HOME Server, providing links to vulnerability details and subscription options, but no exploit or patch information is included.

    0002036
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26366 eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforci… https://www.cve.org/CVERecord?id=CVE-2026-26366

    Post summary

    The CVE discloses that eNet SMART HOME server versions 2.2.1 and 2.3.1 ship with default credentials that persist after installation, exposing a credential management flaw.

    000011.1K
    56.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26366 (CVSS:9.3, CRITICAL) is Undergoing Analysis. eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after ..https://nvd.nist.gov/vuln/detail/CVE-2026-26366 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-26366 as a critical vulnerability in eNet SMART HOME server, highlighting default credentials still active and noting it is currently under analysis.

    0000033
    171 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26366 - Critical eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory passwo... https://www.thehackerwire.com/vulnerability/CVE-2026-26366/ https://t.co/qr6E1lvm65

    Post summary

    The post discloses that eNet SMART HOME server versions 2.2.1 and 2.3.1 ship with default credentials that remain active after installation, representing a critical security weakness.

    0000051
    112 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26366: CRITICAL] eNet SMART HOME server versions 2.2.1 and 2.3.1 have default credentials (user:user, admin:admin) allowing unauthenticated attackers to gain administrative access.#cve,CVE-2026-26366,#cybersecurity https://cvefind.com/CVE-2026-26366

    Post summary

    The tweet discloses that eNet SMART HOME servers 2.2.1 and 2.3.1 contain default credentials, enabling unauthenticated administrative access, but offers no PoC, exploit, or patch information.

    0000050
    580 followersView on X
  • DCWebGuy@DCWebGuy
    PoC

    Gjoko Krstic at Zero Science Lab. CVE-2026-26366 through 26369. Full chain PoC: https://github.com/zeroscience/advisory/tree/master/2026/

    Post summary

    Zero Science Lab released a full chain proof of concept for CVE-2026-26366 through 26369 via a GitHub repository, with no mention of active exploitation, patches, or technical details.

    0000066
    985 followersView on X
  • DCWebGuy@DCWebGuy
    PoC

    Gjoko Krstic at Zero Science Lab. CVE-2026-26366 through 26369. Full chain PoC: https://github.com/zeroscience/advisory/tree/master/2026/

    Post summary

    Zero Science Lab released a full chain PoC for CVE-2026-26366 through 26369, demonstrating the exploitation steps, but the text does not mention active exploitation or any patch or workaround details.

    0000066
    985 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: JUNG eNet SMART HOME servers (v2.2.1 & 2.3.1) ship with default creds, exposing homes & buildings to remote admin takeover! Change passwords NOW 🛡️ https://radar.offseq.com/threat/cve-2026-26366-use-of-default-credentials-in-jung--23983d02 #OffSeq #IoTSecurity #Sma... https://t.co/MIt7pnsCUP

    Post summary

    The tweet highlights that Jung eNet SMART HOME servers ship with default credentials that could enable remote admin takeover and urges users to change passwords immediately.

    0000038
    265 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjung-groupenet_smart_home2.2.1--
Appjung-groupenet_smart_home2.3.1--

Explore more