Network-reachable BioFlo 320 units with VNC enabled are open to full operator takeover. A hard-coded password defeats normal account controls, and unencrypted VNC lets anyone on the path observe the session. CISA says CVE-2026-7251 affects all BioFlo 320 versions. A remote attacker who knows the device address and can reach the enabled VNC service can control the full UI; Eppendorf’s update removes VNC access from the controller. That changes the trust model for any site that ever enabled remote access on the controller. The risk sits in the remote channel itself, so ordinary password assumptions do not apply.
Part of the PlainSec briefing for 2026-05-26