CVE-2026-21411

HIGH

OpenBlocks <FW5.0.8 - Auth Bypass

Title source: llm
STIX 2.1

Description

Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password.

Scores

CVSS v3 8.8
EPSS 0.0005
EPSS Percentile 16.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-288
Status published
Products (6)
Plat'Home Co.,Ltd./OpenBlocks IDM RX1 (FW5.0.x) all versions prior to FW5.0.8
Plat'Home Co.,Ltd./OpenBlocks IoT DX1 (FW5.0.x) all versions prior to FW5.0.8
Plat'Home Co.,Ltd./OpenBlocks IoT EX/BX models (FW5.0.x) all versions prior to FW5.0.8
Plat'Home Co.,Ltd./OpenBlocks IoT FX1 (FW5.0.x) all versions prior to FW5.0.8
Plat'Home Co.,Ltd./OpenBlocks IoT VX2 (FW5.0.x) all versions prior to FW5.0.8
Plat'Home Co.,Ltd./OpenBlocks IX9 models with FW (FW5.0.x) all versions prior to FW5.0.8
Published Jan 06, 2026
Tracked Since Feb 18, 2026