nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-56428 CVE-2026-56428
HIGH
BSH ELP Modules Default SSH Key Authentication Bypass
Record summary
CVE-2026-56428 has a selected CVSS score of 8.1 (high).
Description
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 30, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
BSH ELP (Electronic Platform) ModulesBrowse Bosch / BSH ELP (Electronic Platform) Modules | CVE List | 65.0.0 to < 65.2.12 | affected |
References
2psirt.bosch.comVendor advisory
https://psirt.bosch.com/security-advisories/BOSCH-SA-943700.html