CVE-2026-33272Medium· 4.9▾ SunlitA malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106602Medium· 4.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack jetpack allows Password Recovery Exploitation.This issue affects Jetpack: from n/a through 16.2.
CVE-2026-106601Medium· 5.4Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack jetpack allows Password Recovery Exploitation.This issue affects Jetpack: from n/a through 16.2.
CVE-2025-34251NoneTesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability
CVE-2025-6388Critical· 9.8The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.2.14
CVE-2025-10653High· 8.6An unauthenticated debug port may allow access to the device file system.
CVE-2025-61673High· 8.6Karapace is an open-source implementation of Kafka REST and Schema Registry