CVE-2026-80253CWE-1263

CVE-2026-80253

Medium · published September 3, 2026

CVSS v3.0
6.8
EPSS
0%
Percentile
25.7
In the wild
Unconfirmed
What it is

An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands without authentication.

The record
Technical detail
CVSS v3.0
6.8 · MEDIUM
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
7.0 · CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00330 · 25.7th percentile
Weakness
CWE-1263 · Improper Physical Access Control
Published
2026-09-03T17:06Z
References (2)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 03 SEP 08:54Z
    An improper physical access control issue exists in ShizenBox2 (dev-conf)
    cvelistv5