#VU121566 Improper Authentication in JuiceBox 40 - CVE-2026-0778
Published: January 15, 2026
Vulnerability identifier: #VU121566
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-0778
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
JuiceBox 40
JuiceBox 40
Software vendor:
Enel X
Enel X
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests within the telnet service. A remote attacker on the local network can bypass authentication process and execute arbitrary code on the target system.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.