CVE-2026-8979 Details
Description
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST request to the /operator/operator endpoint.
An authentication bypass vulnerability has been identified in the Mennekes Amtron series, specifically in firmware versions through 5.22.3. This vulnerability allows an unauthenticated remote attacker to change the password of a user account by sending a crafted POST request to the /operator/operator endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 28, 2026CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cyberdanube.com/security-research/multiple-vulnerabilities-in-mennekes-amtron-series/ | CISA-ADP | BundleExploitRemedyTechnical Analysis |
| https://cyberdanube.com/security-research/multiple-vulnerabilities-in-mennekes-amtron-series/ | [email protected] | BundleExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mennekes Amtron Professional | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Amtron Professional Eichrecht | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Amedio Professional | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Amtron Charge Control | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Amtron Professional Twincharge | <= 5.22.3 (semver) |
CPE
Remediation
| |
| Mennekes Smart-T PnC | <= 5.22.3 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | New CVE Received | [email protected] |
Volerion