CVE-2026-80253 Details
Description
An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands without authentication.
A vulnerability exists in ShizenBox2 (dev-conf) versions through 1.0.10, allowing an attacker with physical access to the device to execute bootloader commands without authentication. This issue arises from the absence of a login password for the U-Boot bootloader, enabling unauthorized access to the root filesystem via the serial console.
Users are advised to update to ShizenBox2 dev-conf version 1.1.0 or later. This update includes a password-protected U-Boot binary that is automatically distributed to devices via a firmware-over-the-air (FOTA) update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 3, 2026CISA-ADP
Assessed Sep 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN91715694/ | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.se-digital.net/wp-content/uploads/2026/08/CVE-2026-80253.pdf | [email protected] | Partial ContentRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1263 | Improper Physical Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Shizen Connect Inc. ShizenBox2 | <= 1.0.10 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2026 | New CVE Received | [email protected] |
Volerion