Eppendorf BioFlo 320 bioreactors are affected by a critical vulnerability (CVE-2026-7251, CVSS 9.8) involving a hard-coded password in the VNC server. If VNC is enabled, remote attackers can exploit this flaw to gain full control over the bioreactor's user interface and data. Eppendorf has released a software update (Version 5.0) that permanently removes VNC functionality to mitigate the risk.
Hard-coded Password
1 post
Eppendorf BioFlo 320