Security Advisory – June, 2026: Improved Admin Password Protection and Brute-Force Lockout
Advisory ID: NEAT-SA-2026-06-13
Publication date: June 13, 2026
Last updated: June 13, 2026
Severity: Medium
CVSS vector: Not scored
CVE ID: Not applicable
Summary
Prior to NeatOS 26.1.0, Neat devices did not require administrators to change the factory default admin password on first use, and did not limit the number of failed sign-in attempts against the admin interface, creating a brute-force risk against default or weak credentials. NeatOS 26.1.0 introduces a mandatory password change on first sign-in with the factory default password, and a temporary lockout after repeated failed sign-in attempts.
Affected Products
| Product | Affected versions | Fixed version |
| All Neat devices | NeatOS prior to 26.1.0 | NeatOS 26.1.0 or later |
Impact
Before this fix, an attacker with network access to a device’s admin interface could attempt unlimited password guesses against the factory default credential, and devices left on the factory default password had no forced prompt to change it. Successful exploitation would grant administrative access to the device, including configuration changes and the ability to factory reset it.
Details
NeatOS 26.1.0 makes three related changes: (1) devices running NeatOS 26.x or later require administrators to set a new, unique password the first time they sign in with the factory default password; (2) repeated failed sign-in attempts now trigger a temporary account lockout to reduce the risk of brute-force attacks; (3) administrators can set and update device passwords centrally through Neat Pulse. Neat has stated these changes align with the EN 18031 (EU radio equipment cybersecurity) and UK PSTI (Product Security and Telecommunications Infrastructure Act) requirements.
Remediation
Update to NeatOS 26.1.0 or later. If the admin password has already been changed from the factory default (for example, via Neat Pulse or a configuration profile), no further action is required — the device will not prompt for another change. Devices still on the factory default password will be prompted to set a new password on next sign-in.
Acknowledgements
Not applicable — identified and addressed proactively by Neat, in part to align with incoming regulatory requirements (EN 18031, UK PSTI).
References
- Neat devices: Version 26.1.0 Release Notes
- CWE-307: Improper Restriction of Excessive Authentication Attempts
Contact
Questions about this advisory can be directed to security@neat.no.