A security researcher has discovered that default passwords in a widely used access control system allow anyone to easily gain (remotely) access to door locks and elevators in dozens of buildings in the US and Canada.

Hirsch ,the company that now owns the Enterphone MESH, will not fix the problem in question. It says the flaw is by design and that customers should follow its instructions and change the default password on the system.
It is estimated that there are dozens of exposed homes and offices across North America either because the access codes have not been changed or because administrators are unaware that they should have, according to Eric Daigle (who found the dozens of exposed buildings).
See also: Gmail will soon switch to QR codes over SMS
Default passwords are not uncommon or necessarily secret on devices connected to the internet. These passwords are designed to simplify access and are often found in the device's instruction manual. This means that anyone can find this password. The researcher argues that companies should not rely on customers changing the default password to prevent any future malicious access. When this happens, we are talking about the existence of a serious vulnerability in the product.
In the case of Hirsch's entry systems, customers who install the system are not prompted or required to change the default password. As such, Daigle was credited with discovering the security flaw, officially tracked as CVE-2025-26793.
Hirsch: There will be no correction
Malicious hackers often use default passwords to log into devices as if they were the legitimate owner. Their goal is to steal data or install malware. In recent years, governments have tried to pressure technology manufacturers to avoid using insecure default passwords.
In the case of Hirsch's access system, the vulnerability is considered critical because of the ease with which anyone can exploit it. Attackers could easily discover the default password on Hirsch's website and gain access to any building system where the passwords have not been changed.
See also: The most popular passwords are cracked in one second
In a post, Daigle said he found the vulnerability last year after discovering one of Hirsch's Enterphone MESH entry panels in a building in Vancouver. Daigle used internet scanning site ZoomEye to search for Enterphone MESH systems that were connected to the internet and found 71 systems that were still relying on default credentials.
Daigle said the default password allows access to the web-based system MESH, which building managers use to manage access to elevators, common areas and door locks for offices and residences. Each system displays the physical address of the building with the MESH system installed, allowing anyone logging in to know which building they have accessed.
Daigle said it was possible to effectively penetrate any of the dozens of exposed buildings within minutes.
See also: The longest and strongest WiFi passwords in the world
Hirsch has not publicly disclosed details about the bug, but said it had contacted its customers about following the product's instruction manual, which also recommends changing passwords.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

As Hirsch does not want to correct the error, some buildings are likely to remain exposed.
To protect against unauthorized access, operators of such entry systems are urged to follow password-related security best practices
Change Default Passwords Immediately: Whenever a system is installed, it is essential to change the default password as soon as possible. This simple step can significantly reduce the risk of unauthorized access.
Use strong and unique passwords: A strong password should consist of multiple characters. Using unique passwords for each system also limits the impact if a system's credentials are compromised.
Regular password changes: It is essential to change passwords regularly, at least every 90 days. This practice can minimize the chances of attacks and keep systems secure.
Training: System administrators must be trained in security best practices and constantly updated on new threats.
Source: techcrunch.com
