VYPR

Amtron series

by Mennekes

CVEs (2)

  • CVE-2026-8980CriMay 28, 2026
    risk 0.60cvss epss

    The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer accounts via crafted POST requests.

  • CVE-2026-8979CriMay 28, 2026
    risk 0.60cvss epss

    The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST request to the /operator/operator endpoint.