CVE-2026-56428
Received
Received - Intake
Improperly Secured Default SSH Key in BSH ELP Modules
Vulnerability report for CVE-2026-56428, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-30
Last updated on: 2026-07-30
Assigner: Robert Bosch GmbH
Description
Description
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| bosch | bsh_elp | From 65.0.0 (inc) to 65.2.11 (inc) |
| bosch | bsh_elp | 65.2.12 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-286 | The product does not properly manage a user within its environment. |