important · Boot chain — Appliance
ShizenBox2 serial access permits a persistent root backdoor through U-Boot.
Affects
Shizen Connect ShizenBox2, an edge appliance administered through the vendor's dev-conf software and booted through U-Boot.
The shipped console had no password and allowed unrestricted rootfs reads and writes after boot interruption through the serial port.
Detail and 6 sources
Authenticated U-Boot began shipping through FOTA with dev-conf 1.1.0.
Sources
ResearchJapan Vulnerability Notes/ベンダーからの情報Researchhttps://se-digital.net/wp-content/uploads/2026/08/CVE-2026-80253.pdfResearchJVN#91715694: Multiple vulnerabilities in ShizenBox2ResearchJVNDB-2026-000127 - JVN iPedia - �Ǝ㐫����f�[�^�x�[�XResearchShizen Connectが電力IoT用エッジ端末「Shizen Box2」を発売 – プレスリリースSecondaryShizenBox2 permits unauthenticated physical bootloader commands