CVE-2026-40639
Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potent
CVSS
5.7
Medium
EPSS
0.2%
p9
KEV
—
Exploit Today
3
0-100
Published: Jun 9, 2026 · Last modified: Jul 23, 2026 · CWE-261
0.1%EPSS · 30 days0.2%
2026-07-012026-07-29
Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-675966.2 MED—
———CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher with a static key applied to the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.7hCVE-2026-25607—0.8%
——0Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded.
This issue was fixed in version 9.5.7d