CVE-2026-41446

CRITICAL

WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints

Title source: cna
STIX 2.1

Description

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device label or documentation containing these values can authenticate to the several endpoints and execute arbitrary commands as root on the device.

Scores

CVSS v3 9.8
EPSS 0.0007
EPSS Percentile 21.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798 CWE-912
Status published
Products (2)
Snap One, LLC/WattBox 800 < 2.10.0.0
Snap One, LLC/WattBox 820 < 2.10.0.0
Published Apr 28, 2026
Tracked Since Apr 29, 2026