What is CVE-2026-49005?
This vulnerability allows the root password hash of the device to be obtained through unencrypted information in the firmware. Due to the lack of protection for sensitive data stored in the firmware, an attacker can use this hash to compromise the entire system. It is recommended to wait for or apply an updated firmware from the manufacturer for affected devices.
Azərbaycanca: Bu boşluq firmvarda şifrələnməmiş məlumatlar vasitəsilə cihazın əsas (root) parol heşinin əldə edilməsinə imkan yaradır. Firmvarda saxlanılan həssas məlumatların qorunmaması səbəbindən təcavüzkar bu heşi istifadə edərək sistemi tam ələ keçirə bilər. Təsirə məruz qalan cihazlar üçün istehsalçının təqdim edəcəyi yenilənmiş firmvarı gözləmək və ya tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
What critical information can an attacker obtain through the CVE-2026-49005 vulnerability?
An attacker can obtain the root password hash of the device through this vulnerability.
What measure should be taken to protect a device from the CVE-2026-49005 vulnerability?
It is recommended to wait for or apply an updated firmware from the manufacturer for affected devices.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.