CVE-2026-56428 Details
Description
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.
A vulnerability in the SSH service on BSH ELP (Electronic Platform) modules has been identified, stemming from a default configuration that is not properly secured. The vulnerability involves an insecure, non-revocable SSH public key that is included in the firmware's authorized_keys file for the root user. An attacker possessing the corresponding private key could exploit this flaw to bypass authentication and gain root-level access to the appliance.
Users are advised to update their home appliance firmware to the latest version. For systems on the '65.x.y' branch, upgrade to version 65.2.12 or higher. For systems on the '7x.y.z' branch, upgrade to version 72.0.0 or higher. If an immediate update is not possible, appliances should be kept on a secure home network, behind a firewalled router, and not exposed to untrusted public networks or the internet.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2026CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://psirt.bosch.com/security-advisories/BOSCH-SA-943700.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-286 | Incorrect User Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bosch BSH ELP | >= 65.0.0, < 65.2.12 (semver) >= 65.0.0, < 65.2.10 (semver) >= 7, < 72.0.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |
Volerion