CVE-2026-8980: Mennekes Amtron
Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer accounts via crafted POST requests.
Affected products
- Mennekes Amtron: up to and including 5.22.3
Published 2026-05-28. Last modified 2026-06-17.