Executive brief
Snap One WattBox 800 and 820 series power distribution units contain hidden diagnostic interfaces that can be accessed using information printed directly on the device's physical label. An attacker who can obtain the device's MAC address and service tag—either through physical access or from documentation—can take full control of the device. This allows for unauthorized command execution with the highest level of privileges, potentially leading to service disruption or further network intrusion.
Technical details
The vulnerability stems from the use of hard-coded or predictable credentials (CWE-798) and hidden functionality (CWE-912) within undisclosed diagnostic HTTP endpoints. These endpoints authenticate users based solely on the device's MAC address and service tag, both of which are typically printed in plaintext on the physical device label or included in setup documentation. A network-based attacker with knowledge of these two values can bypass standard authentication to access these diagnostic tools. Successful exploitation allows the attacker to execute arbitrary commands with root privileges on the underlying operating system. The issue is resolved in firmware version 2.10.0.0.
Affected products
- Snap One WattBox 800 Series prior to 2.10.0.0
- Snap One WattBox 820 Series prior to 2.10.0.0
Timeline
- 2026-03-19: patched: Firmware version 2.10.0.0 released
- 2026-04-28: disclosed: Initial public disclosure
- 2026-04-28: advisory: CVE-2026-41446 published