ZeroHour

CVE-2026-80253

Unauthenticated Bootloader Access via Physical Attack in ShizenBox2

CVSS 4.0
7.0 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-80253 is an improper physical access control flaw (CWE-1263) in ShizenBox2 (dev-conf) that allows an attacker with physical access to the device to execute bootloader commands without authentication. The attack requires the adversary to be physically present at the product; no network or remote exploitation path is indicated. Because bootloader commands are exposed, an attacker could alter low-level device settings or boot behavior with high impact on the device's confidentiality, integrity, and availability, per the CVSS 4.0 score of 7 (High). Any user or organization with the affected ShizenBox2 (dev-conf) hardware deployed in locations where unauthorized persons could physically reach it is affected. There is currently no public proof-of-concept, no entry in CISA's Known Exploited Vulnerabilities catalog, and a low EPSS estimate of 0.3% for exploitation in the next 30 days.

What to do: Check the JPCERT/CC advisory referenced by the CNA ([email protected]) for firmware updates or mitigations and apply the vendor's fixed version as soon as one is published. Until then, restrict physical access to the device to trusted personnel, since exploitation requires hands-on access. Verify your deployed hardware model and record its firmware version so you can confirm patch status when an update is released.

Affected
ShizenBox2 (dev-conf)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands without authentication.

Weakness
CWE-1263
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.