important · Firmware — Appliance
A low-privilege ShizenBox2 user can replace the administrator's password.
Affects
ShizenBox2, a network-connected energy-IoT edge controller used to monitor and control household energy equipment.
The password-change API trusted the username supplied in the request instead of the authenticated session identity.
Detail and 6 sources
Edge-app 3.1.16 binds the operation to the session identity.
Sources
ResearchJapan Vulnerability Notes/ベンダーからの情報Researchhttps://se-digital.net/wp-content/uploads/2026/08/CVE-2026-80254.pdfResearchJVN#91715694: Multiple vulnerabilities in ShizenBox2ResearchShizen Boxがフェールオーバー機能を追加 - Shizen ConnectResearchShizen Connectが電力IoT用エッジ端末「Shizen Box2」を発売 – プレスリリースSecondaryShizenBox2 permits unauthenticated physical bootloader commands