« Volver al listado

CVE-2026-21411

Estado: AplazadaAlta (8.7)—

Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:A (red adyacente) sin privilegios previos indica T1210. CWE-288 (falta de autenticación) permite bypass de credenciales (T1078) y cambio de contraseña de admin (T1098.002).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-21411",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-21411",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-06T14:47:57.055920Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "vultures@jpcert.or.jp",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "vultures@jpcert.or.jp",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Plat'Home Co.,Ltd.",
          "product": "OpenBlocks IoT DX1 (FW5.0.x)",
          "versions": [
            {
              "status": "affected",
              "version": "all versions prior to FW5.0.8"
            }
          ]
        },
        {
          "vendor": "Plat'Home Co.,Ltd.",
          "product": "OpenBlocks IoT EX/BX models (FW5.0.x)",
          "versions": [
            {
              "status": "affected",
              "version": "all versions prior to FW5.0.8"
            }
          ]
        },
        {
          "vendor": "Plat'Home Co.,Ltd.",
          "product": "OpenBlocks IX9 models with FW (FW5.0.x)",
          "versions": [
            {
              "status": "affected",
              "version": "all versions prior to FW5.0.8"
            }
          ]
        },
        {
          "vendor": "Plat'Home Co.,Ltd.",
          "product": "OpenBlocks IoT VX2 (FW5.0.x)",
          "versions": [
            {
              "status": "affected",
              "version": "all versions prior to FW5.0.8"
            }
          ]
        },
        {
          "vendor": "Plat'Home Co.,Ltd.",
          "product": "OpenBlocks IDM RX1 (FW5.0.x)",
          "versions": [
            {
              "status": "affected",
              "version": "all versions prior to FW5.0.8"
            }
          ]
        },
        {
          "vendor": "Plat'Home Co.,Ltd.",
          "product": "OpenBlocks IoT FX1 (FW5.0.x)",
          "versions": [
            {
              "status": "affected",
              "version": "all versions prior to FW5.0.8"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-01-06T07:15:43.870",
  "references": [
    {
      "url": "https://jvn.jp/en/vu/JVNVU97172240/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.plathome.co.jp/support/software/fw5/dx1-v5-0-8/",
      "source": "vultures@jpcert.or.jp"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vultures@jpcert.or.jp",
      "description": [
        {
          "lang": "en",
          "value": "CWE-288"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password."
    },
    {
      "lang": "es",
      "value": "Existe un problema de omisión de autenticación en las versiones de la serie OpenBlocks anteriores a FW5.0.8, lo que podría permitir a un atacante omitir la autenticación de administrador y cambiar la contraseña."
    }
  ],
  "lastModified": "2026-06-17T10:18:37.713",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}