Published:2026/09/02 Last Updated:2026/09/02
JVN#91715694
Multiple vulnerabilities in ShizenBox2
Overview
ShizenBox2 provided by Shizen Connect Inc. contains multiple vulnerabilities.
Products Affected
CVE-2026-80253
- ShizenBox2 (dev-conf) v1.0.10 and earlier
- ShizenBox2 (edge-app) v3.1.15 and earlier
Description
ShizenBox2 provided by Shizen Connect Inc. contains multiple vulnerabilities listed below.
- Improper physical access control (CWE-1263)
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 7.0
- CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 6.8
- CVE-2026-80253
- Authorization bypass through user-controlled key (CWE-639)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Base Score 7.1
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Base Score 6.5
- CVE-2026-80254
Impact
- An attacker with physical access to the product may execute bootloader commands without authentication (CVE-2026-80253).
- An attacker who can log in to the product may change the other user's password (CVE-2026-80254).
Solution
Update the product
Update the product to the latest version according to the information provided by the developer.
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
CVE-2026-80253
Naohide Waguri of PwC Consulting LLC reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVE-2026-80254
Raaqim Mohammed of PwC Consulting LLC reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-80253 |
|
CVE-2026-80254 |
|
| JVN iPedia |
JVNDB-2026-000127 |