External risk intelligence

EVbee DC-80 Firmware Weak Hardcoded Root Password Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-22094

The vulnerability involves a hardcoded root password accessible via an SSH daemon on a network-connected device. Devices such as the EVbee DC-80 often require network connectivity for management or operation, and SSH services on such hardware are frequently exposed or reachable within the network environment where they are deployed.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

The EVbee DC-80 firmware contains a weak, hardcoded root password that, if exploited, could allow unauthorized network access as a root user.

  • Weak password allows network root access.
  • Confirms exposure of critical infrastructure.
  • Verify if any devices are in use.

Attack Path

How an attacker could exploit the issue

An attacker could leverage a weak hardcoded root password to gain privileged access to the device's firmware through its network-exposed SSH daemon. Once authenticated as root, the attacker could potentially manipulate the system's core functionalities, leading to a critical compromise.

  • Accessible over the network.
  • Login as root via SSH.
  • Complete system compromise.

Live Threat

Current exploitation, exposure, and threat context

The firmware for the EVbee DC-80 includes a weak, hardcoded root password. When the SSH daemon is exposed to the network, an attacker could use this password to log in as root.

  • Device firmware and configuration.
  • Network login via SSH.
  • Unauthorized root access to the device.

Operational Fix

Recommended remediation, mitigation, and detection steps

The EVbee DC-80's hardcoded root password issue likely falls under the responsibility of the infrastructure or IoT platform team managing the devices. The first practical step is to identify all deployed EVbee DC-80 units, determine their network reachability and business criticality, and locate the accountable owner for remediation planning.

  • Infrastructure or IoT platform teams own this.
  • Verify network exposure and asset criticality.
  • Plan vendor engagement and firmware updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the EVbee DC-80?

The EVbee DC-80 is a hardware device that utilizes firmware to manage its core operations. These devices often require network connectivity for management tasks, and they are typically deployed in infrastructure environments where reliable, connected operation is required for their intended service.

What does CVE-2026-22094 mean for security?

This vulnerability is classified as CWE-1391, which refers to the use of hardcoded credentials. In this specific case, it means the device comes with a fixed, unchangeable root password built into its firmware. Because this password is known, an unauthorized person could use it to gain full administrative control over the device.

How can an attacker trigger this vulnerability?

An attacker triggers this by connecting to the device's SSH daemon over the network and providing the hardcoded root password. The vulnerability is specifically linked to this SSH access; it does not typically affect local console access or other non-networked management interfaces that do not utilize the vulnerable SSH service.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal identifies this as a 'Likely' concern because these devices are often deployed with their management interfaces reachable across a network. If your specific unit's SSH daemon is reachable from outside your local network or is exposed on an internal network, it is a primary candidate for unauthorized access.

Do I need to patch the EVbee DC-80 immediately?

You should begin by auditing your infrastructure to locate all active EVbee DC-80 units and confirming which ones are connected to the network. Once you have an inventory, coordinate with your internal IT or IoT platform teams to assess the device's network visibility and contact the vendor for guidance on firmware updates.

References