Vulnerabilities & Exploits

Fixed VNC Password Exposes BioFlo 320 Control

Network-reachable BioFlo 320 units with VNC enabled are open to full operator takeover. A hard-coded password defeats normal account controls, and unencrypted VNC lets anyone on the path observe the session.

CISA says CVE-2026-7251 affects all BioFlo 320 versions. A remote attacker who knows the device address and can reach the enabled VNC service can control the full UI; Eppendorf’s update removes VNC access from the controller.

That changes the trust model for any site that ever enabled remote access on the controller. The risk sits in the remote channel itself, so ordinary password assumptions do not apply.

1 source · May 26

CVE-2026-7251

NVD KEV

CVSS 9.8 CRITICAL: eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password.

Timeline

Sources

Part of the PlainSec briefing for 2026-05-26

Every edition of this story: Fixed VNC Password Exposes BioFlo 320 Control

More from today