CVE-2026-8979: Mennekes Amtron

Critical severity, CVSS 9.3. EPSS: 0.7% chance of exploitation in the next 30 days.

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST request to the /operator/operator endpoint.

Affected products

  • Mennekes Amtron: up to and including 5.22.3

Published 2026-05-28. Last modified 2026-06-17.