CVE-2026-8980: Mennekes Amtron

Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer accounts via crafted POST requests.

Affected products

  • Mennekes Amtron: up to and including 5.22.3

Published 2026-05-28. Last modified 2026-06-17.