news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-7251

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.8 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Risk score
78.4
Published
2026-05-26
Status
Awaiting Analysis

Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.

Weaknesses

CWE-259

Coverage 1

vulnerability

Eppendorf BioFlo 320

This CISA advisory details a critical vulnerability in Eppendorf BioFlo 320 bioreactors due to a hard-coded VNC password, allowing unauthorized remote access and control. The vulnerability affects all versions of the Bio…

CISA Advisories · May 26, 2026 Critical

Advisories and references