CVE-2026-7251
CVSS 9.8 CRITICAL: eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password.
Vulnerabilities & Exploits
Network-reachable BioFlo 320 units with VNC enabled are open to full operator takeover. A hard-coded password defeats normal account controls, and unencrypted VNC lets anyone on the path observe the session.
CISA says CVE-2026-7251 affects all BioFlo 320 versions. A remote attacker who knows the device address and can reach the enabled VNC service can control the full UI; Eppendorf’s update removes VNC access from the controller.
That changes the trust model for any site that ever enabled remote access on the controller. The risk sits in the remote channel itself, so ordinary password assumptions do not apply.
1 source · May 26
CVSS 9.8 CRITICAL: eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password.
CISA Advisories
Eppendorf BioFlo 320 | CISA
Eppendorf BioFlo 320 Summary Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor.
originalPart of the PlainSec briefing for 2026-05-26
Every edition of this story: Fixed VNC Password Exposes BioFlo 320 Control