---
id: CVE-2026-22101
title: >-
  The access to the service menu is obfuscated, but possible with only physical
  access
summary: >-
  The access to the service menu is obfuscated, but possible with only physical
  access. This menu exposes sensitive information such as serial numbers, MAC
  addresses, and WiFi network and password.
severity: medium
cvss: 5.1
cvssVector: 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-200
vendor: EVbee
product: DC-80
affected:
  - DC-80 unknown
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T15:17:25.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-22101'
references:
  - url: 'https://csirt.divd.nl/DIVD-2026-00001/'
    label: csirt@divd.nl
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T16:39:33.259Z'
---

## Overview

The access to the service menu is obfuscated, but possible with only physical access. This menu exposes sensitive information such as serial numbers, MAC addresses, and WiFi network and password.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
