Executive brief
ShizenBox2 is a network appliance used for edge computing and device management. An attacker with physical access to a vulnerable device can bypass authentication to execute bootloader commands, potentially gaining complete control over the system. This could allow an attacker to extract sensitive data, install malware, or disable the device entirely.
Technical details
An improper physical access control vulnerability (CWE-1263) exists in ShizenBox2 dev-conf versions 1.0.10 and earlier. The bootloader does not properly enforce authentication, allowing an attacker with physical access to the device to execute arbitrary bootloader commands without credentials. This requires direct physical access to the target device and no authentication, but provides high impact—allowing complete system compromise including confidentiality, integrity, and availability violations. No patch is currently available; the vendor advises updating to the latest version once released.
Affected products
- Shizen Connect Inc. ShizenBox2 1.0.10 and earlier
Timeline
- 2026-09-02: disclosed
- 2026-09-03: advisory