CVE-2025-26793 identifies a critical vulnerability in Hirsch Enterphone MESH systems (through 2024) due to default credentials (freedom/viscount) that administrators are not prompted to change and are difficult to modify. Rated 10.0 Critical (CVSSv4), this vulnerability allows unauthenticated attackers to remotely access the system over the Internet, potentially compromising apartment building access and residents' Personally Identifiable Information (PII). Although not in the CISA KEV catalog, exploit code (Nuclei templates) is publicly available, it is on the Hot List, and there is active community discussion regarding its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Hirsch | Enterphone MESH | >= 0, <= 2024CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.