Junglewise Threat Intelligence

CVE-2026-56428: Bosch BSH ELP Modules hardcoded SSH key in root account

CVE-2026-56428 · Severity: high · CVSS 8.1 · Published 2026-07-30

Executive brief

Bosch BSH ELP modules are the electronic brains used in connected home appliances from brands like Bosch, Siemens, Gaggenau, and Neff. A security flaw in these modules includes a permanent, non-removable master key in the system's configuration. If an attacker obtains the matching private key, they could gain full administrative control over the appliance, potentially leading to data theft, service disruption, or unauthorized remote operation.

Technical details

This vulnerability is a case of incorrect user management (CWE-286) within the default firmware configuration of Bosch BSH ELP modules. The firmware's authorized_keys file for the root user contains a hardcoded, non-revocable SSH public key. While the attack complexity is rated high (likely due to the requirement of obtaining the specific private key), a successful exploit allows a remote, unauthenticated attacker to bypass SSH authentication entirely. This provides full root-level access to the underlying operating system. The issue is addressed in firmware version 65.2.12 and higher, which is typically delivered via over-the-air (OTA) updates.

Affected products

  • Bosch BSH ELP (Electronic Platform) Modules 65.0.0 < 65.2.12

Timeline

  • 2026-07-30: advisory: Initial publication of BOSCH-SA-943700
  • 2026-07-30: disclosed

References