CVE-2026-14169
Received Received - Intake

Incorrect Password Reset Leading to Full Administrative Denial in Device Firmware

Vulnerability report for CVE-2026-14169, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: CERT VDE

Description

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-696 The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a low-privileged remote attacker to manipulate input in a way that triggers an inconsistent account state. The attacker can overwrite existing user passwords, leading to complete administrative unavailability of the affected device.

Impact Analysis

An attacker could gain full administrative control over the device by changing passwords, making it inaccessible to legitimate users. This could disrupt operations, cause data loss, or enable further attacks.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection requirements in GDPR and HIPAA. It may result in non-compliance due to potential data breaches or loss of administrative control over sensitive systems.

Mitigation Strategies

Apply vendor patches or updates immediately to fix the incorrect behavior order. Restrict remote access to trusted sources only and monitor for unauthorized password changes or account inconsistencies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14169. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart