PULSE
FEED
ransomm3rx reclama a intense.pl · PL · Technologyransomkairos reclama a Unique Repair Services · US · Otherransomchaos reclama a advantech.com · TW · Manufacturingransominterlock reclama a Tekko Enterprises, Inc · US · Not Foundransomwallstreet reclama a Gibson Area Hospital & Health Services · US · Healthcareransomemperador reclama a Polikem · TR · Manufacturingransomgammax reclama a AHeadStart Tutoring · NZ · Educationransomgammax reclama a Crowder Industries, Inc · US · Manufacturingransombraincipher reclama a latitudesubro.com · BR · Manufacturingransomlockbit5 reclama a spg.co.kr · KR · Otherransombraincipher reclama a trailerbridge.com · US · Transportationransombraincipher reclama a mccordclaims.com · US · Financial Servicesransombraincipher reclama a goriteway.com · GE · Not Foundransombraincipher reclama a mulholland.com · US · Not Foundransomm3rx reclama a intense.pl · PL · Technologyransomkairos reclama a Unique Repair Services · US · Otherransomchaos reclama a advantech.com · TW · Manufacturingransominterlock reclama a Tekko Enterprises, Inc · US · Not Foundransomwallstreet reclama a Gibson Area Hospital & Health Services · US · Healthcareransomemperador reclama a Polikem · TR · Manufacturingransomgammax reclama a AHeadStart Tutoring · NZ · Educationransomgammax reclama a Crowder Industries, Inc · US · Manufacturingransombraincipher reclama a latitudesubro.com · BR · Manufacturingransomlockbit5 reclama a spg.co.kr · KR · Otherransombraincipher reclama a trailerbridge.com · US · Transportationransombraincipher reclama a mccordclaims.com · US · Financial Servicesransombraincipher reclama a goriteway.com · GE · Not Foundransombraincipher reclama a mulholland.com · US · Not Found
← All CVEs
CVE WatchSep 29, 2026

CVE-2026-7193

A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attacker connected to the

CVSS

—

No CVSS

EPSS

—

KEV

—

Exploit Today

0

0-100

Published: Sep 29, 2026 · Last modified: Sep 29, 2026 · CWE-798

EPSS · 30d

Not enough EPSS history yet.

Technical description

A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attacker connected to the same network to gain full root access to the device via the Telnet service (port 23) using static credentials.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-9658710.0 CRI
—
——0The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.5h
CVE-2026-1002947.5 HIG
—
——0In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.5h
CVE-2026-1010527.3 HIG
36.8%
——11A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token Handler. The manipulation with the input test leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.2d
CVE-2026-799596.8 MED
6.1%
——2The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.4d
CVE-2026-932905.5 MED
1.2%
——0Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.5d
CVE-2026-965485.6 MED
16.1%
——5A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.6d