The Eppendorf BioFlo 320 bioprocess control station, all versions, uses a hard-coded password on its VNC remote-access interface. ICSMA-26-146-01, CVE-2026-7251, base score 9.8. Reach the interface, use the baked-in password, own the bioreactor, which on a bioprocess controller means the ability to manipulate the process itself. BIO-ISAC reported it, which says the biomanufacturing sector is starting to watch its own instruments the way hospitals watch theirs.
The password is in the firmware, and every unit ships with the same one. No interim mitigation beats network isolation here. Get the VNC interface off any reachable segment and wait for the fix.
Questions & Answers
What is CVE-2026-7251 in the Eppendorf BioFlo 320?
The BioFlo 320 bioprocess controller ships a hard-coded password on its VNC remote-access interface. Anyone who can reach that interface gets full control of the controller, which is why it carries a 9.8 base score.
Can it be exploited remotely?
Yes, if the VNC interface is reachable over the network. The credential is fixed in the product, so no guessing or brute force is needed once an attacker has a network path to the device.
What should a lab or manufacturer do about it?
Restrict access to the VNC interface and put the device behind network segmentation, then apply the remediation in ICSMA-26-146-01. Rotating the password is not enough on its own because it is built into the product.