CVE-2026-80253
—Unauthenticated Bootloader Access via Physical Attack in ShizenBox2
CVE-2026-80253 is an improper physical access control flaw (CWE-1263) in ShizenBox2 (dev-conf) that allows an attacker with physical access to the device to execute bootloader commands without authentication. The attack requires the adversary to be physically present at the product; no network or remote exploitation path is indicated. Because bootloader commands are exposed, an attacker could alter low-level device settings or boot behavior with high impact on the device's confidentiality, integrity, and availability, per the CVSS 4.0 score of 7 (High). Any user or organization with the affected ShizenBox2 (dev-conf) hardware deployed in locations where unauthorized persons could physically reach it is affected. There is currently no public proof-of-concept, no entry in CISA's Known Exploited Vulnerabilities catalog, and a low EPSS estimate of 0.3% for exploitation in the next 30 days.
What to do: Check the JPCERT/CC advisory referenced by the CNA ([email protected]) for firmware updates or mitigations and apply the vendor's fixed version as soon as one is published. Until then, restrict physical access to the device to trusted personnel, since exploitation requires hands-on access. Verify your deployed hardware model and record its firmware version so you can confirm patch status when an update is released.
| ShizenBox2 (dev-conf) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands without authentication.
- Weakness
- CWE-1263
- Vector
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.