#VU121566 Improper Authentication in JuiceBox 40 - CVE-2026-0778

 

#VU121566 Improper Authentication in JuiceBox 40 - CVE-2026-0778

Published: January 15, 2026


Vulnerability identifier: #VU121566
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-0778
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
JuiceBox 40
Software vendor:
Enel X

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing authentication requests within the telnet service. A remote attacker on the local network can bypass authentication process and execute arbitrary code on the target system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links