CVE-2026-49006
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
CVSS
5.3
Medium
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Published: Aug 7, 2026 · Last modified: Aug 7, 2026 · CWE-321
Not enough EPSS history yet.
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-54218—37.5%
——11Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various
files using only obfuscation. Any user with access to the server’s file
system, or who can otherwise extract files from the server (see
vulnerability “Random File Read”), can potentially obtain affected
users’ passwords. This issue affects TeamDavid through Rollout 524.2dCVE-2026-490086.5 MED7.1%
——2By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific application function on the device.2dCVE-2026-184118.1 HIG26.1%
——8The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.3dCVE-2026-148049.1 CRI22.8%
——7Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.5dCVE-2026-187549.1 CRI23.7%
——7The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.5dCVE-2026-187539.1 CRI23.7%
——7The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.5d