[Japanese]

JVNDB-2026-000127

Multiple vulnerabilities in ShizenBox2

Overview

ShizenBox2 provided by Shizen Connect Inc. contains multiple vulnerabilities listed below.
  • Improper physical access control (CWE-1263) - CVE-2026-80253
  • Authorization bypass through user-controlled key (CWE-639) - CVE-2026-80254
CVE-2026-80253
Naohide Waguri of PwC Consulting LLC reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-80254
Raaqim Mohammed of PwC Consulting LLC reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
  • Attack Vector: physics
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
CVSS v4 Severity
Base Metrics: 7.0 (High) [IPA Score]
  • Access Vector (AV): Physical
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): High
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-80253


CVSS v3 Severity
Base Metrics: 6.5(Medium) [IPA Score]
  • Access Vector : Network
  • Attack Complexity : Low
  • Privileges Required : Low
  • User Interaction : None
  • Scope : Unchanged
  • Confidentiality Impact : None
  • Integrity Impact : High
  • Availability Impact : None
CVSS v4 Severity
Base Metrics: 7.1 (High) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): None
  • Integrity Impact (VI): High
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-80254
Affected Products


Shizen Connect Inc.
  • ShizenBox2 (dev-conf) v1.0.10 and earlier (CVE-2026-80253)
  • ShizenBox2 (edge-app) v3.1.15 and earlier (CVE-2026-80254)

Impact

  • An attacker with physical access to the product may execute bootloader commands without authentication (CVE-2026-80253).
  • An attacker who can log in to the product may change the other user's password (CVE-2026-80254).
Solution

[Update the product]
Update the product to the latest version according to the information provided by the developer.
Vendor Information

Shizen Connect Inc.
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-80253
  2. CVE-2026-80254
References

  1. JVN : JVN#91715694
Revision History

  • [2026/09/02]
      Web page was published