What is CVE-2026-56428?
The SSH service on BSH ELP modules contains a vulnerability due to a non-revocable, insecure SSH public key hardcoded for the root user in the firmware's authorized_keys file. An attacker possessing the corresponding private key can gain unauthorized root access to the device. It is recommended to restrict network access to the SSH service until an official firmware fix is provided by the vendor.
Azərbaycanca: BSH ELP modullarında SSH xidməti, root istifadəçisi üçün firmware-də yerləşdirilmiş bərpa olunmayan etibarsız SSH açıq açarı səbəbindən icazəsiz giriş zəifliyi mövcuddur. Bu, uyğun xüsusi açarı ələ keçirən hücumçuya cihazda tam nəzarət imkanı yaradır. Cihaz istehsalçı tərəfindən yenilənməyincə, SSH xidmətini şəbəkə səviyyəsində məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which BSH devices are affected by CVE-2026-56428?
BSH ELP modules are affected by this vulnerability.
What mitigation is recommended for CVE-2026-56428 until a vendor patch is available?
It is recommended to restrict network access to the SSH service until an official firmware fix is provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.