CVE-2023-29126: Enelx Waybox Pro Firmware

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.

Affected products

  • Enelx Waybox Pro Firmware: before 2.1.1.0_jb3vu096a (fixed in 2.1.1.0_jb3vu096a)

Published 2024-11-05. Last modified 2026-06-17.