HIGHCVE-2026-21411Published Modified CNA jpcert
CVE-2026-21411: Authentication bypass issue exists in OpenBlocks series versions prior to FW5
Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password.
Metrics
- CVSS v4.0
- 8.7
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 6
Affected packages
- Plat'Home Co.,Ltd. / OpenBlocks IoT DX1 (FW5.0.x)all versions prior to FW5.0.8
- Plat'Home Co.,Ltd. / OpenBlocks IoT EX/BX models (FW5.0.x)all versions prior to FW5.0.8
- Plat'Home Co.,Ltd. / OpenBlocks IX9 models with FW (FW5.0.x)all versions prior to FW5.0.8
- Plat'Home Co.,Ltd. / OpenBlocks IoT VX2 (FW5.0.x)all versions prior to FW5.0.8
- Plat'Home Co.,Ltd. / OpenBlocks IDM RX1 (FW5.0.x)all versions prior to FW5.0.8
- Plat'Home Co.,Ltd. / OpenBlocks IoT FX1 (FW5.0.x)all versions prior to FW5.0.8
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NReferences