CVE-2026-7251
CVSS 9.8 CRITICAL: eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password.
Vulnerabilities · 111 days ago
Network-reachable BioFlo 320 units with VNC enabled are open to full operator takeover. A hard-coded password defeats normal account controls, and unencrypted VNC lets anyone on the path observe the session.
CISA says CVE-2026-7251 affects all BioFlo 320 versions. A remote attacker who knows the device address and can reach the enabled VNC service can control the full UI; Eppendorf’s update removes VNC access from the controller.
That changes the trust model for any site that ever enabled remote access on the controller. The risk sits in the remote channel itself, so ordinary password assumptions do not apply.
CVSS 9.8 CRITICAL: eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password.
1 source covering this story
Eppendorf BioFlo 320 Summary Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor.
Part of the PlainSec briefing for 2026-05-26