CVE-2023-36623: Loxone Miniserver Go Gen 2 Firmware

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user to calculate the root password and escalate privileges.

Affected products

  • Loxone Miniserver Go Gen 2 Firmware: before 14.2 (fixed in 14.2)

Published 2023-07-05. Last modified 2026-06-17.