eNet Smart Home Server Default Credentials Vulnerability
Vulnerability
A vulnerability exists in eNet SMART HOME server versions 2.2.1 and 2.3.1, where the application is shipped with default credentials that remain active after installation. The default usernames and passwords (user:user and admin:admin) do not require a mandatory password change, allowing unauthenticated attackers to gain administrative access to sensitive smart home configurations and control functions.
Impact
Exploitation of this vulnerability allows for unauthorized administrative access, enabling attackers to manipulate sensitive smart home settings and controls.
Added: Feb 15, 2026, 4:19 PM
Updated: Feb 15, 2026, 4:19 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
8.7remediation
0.0relevance
2.8threat
6.4urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
