CVE-2026-73778CWE-521

CVE-2026-73778

High · published September 2, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
18.9
In the wild
Unconfirmed
What it is

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00270 · 18.9th percentile
Weakness
CWE-521 · Weak Password Requirements
Published
2026-09-02T01:18Z
References (1)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 01 SEP 20:28Z
    Credential Manager Vulnerability Allows Unauthorized Administrative Access
    cvelistv5