CVE-2026-41446Patch

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device label or documentation containing these values can authenticate to the several endpoints and execute arbitrary commands as root on the device.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798CWE-912

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-29: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-29: 104-29
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.2 CVSS flaw in WattBox 800/820 controllers (CVE-2026-41446) allows root RCE using plaintext hardware labels. Upgrade to firmware v2.10.0.0 now. #WattBox #CyberSecurity #InfoSec #RootAccess #HardwareSecurity #PatchNow #SnapOne #IoT https://securityonline.info/wattbox-800-820-series-vulnerability-cve-2026-41446-root-exploit/ https://t.co/ShxUiIViCP

    Post summary

    The tweet announces a critical CVE (CVE-2026-41446) in WattBox controllers, describing a root RCE vector via plaintext hardware labels and urging an immediate firmware upgrade to v2.10.0.0.

    01031284
    12.5K followersView on X

Explore more