ICS Medical Advisory | Eppendorf BioFlo 320
CISA warns that Eppendorf BioFlo 320 bioreactors can expose full control through a hard-coded VNC password. The vendor says a software update removes VNC access.
Intelligence analysis by GPT-5.4 Mini
CISA says a critical flaw in Eppendorf BioFlo 320 systems could let a remote attacker take over the interface and reach control and data. The advisory says the vendor has issued a software update that permanently removes VNC access.
A machine used in labs and medical work had a secret door that was too easy to open. The company and CISA say someone on the network could use a hidden password to get inside and press the controls.
That matters because this is not a toy. If the wrong person gets in, they could change settings, see data, or interfere with how the machine works, like taking over a remote-control car from far away.
CISA says the fix is to install the vendor’s update, which removes that remote access path. It also says these machines should stay protected behind strong barriers, not left open to the internet.
Analysis
What CISA reported
CISA published an ICS Medical Advisory for the Eppendorf BioFlo 320, listing a critical vulnerability with a CVSS score of 9.8. The advisory says successful exploitation could give an attacker full access to the bioreactor’s functionality and data.
The flaw
The issue is identified as CVE-2026-7251. CISA says the affected product uses a hard-coded password in its VNC server. If a remote attacker knows the network address of a BioFlo 320 unit with remote access enabled, they can use that password to take control of the user interface. Once connected, the attacker would have access to all control panel features. CISA also notes that the VNC traffic is not encrypted.
What Eppendorf says to do
Eppendorf has released a software update that permanently removes VNC access from the controller. The advisory says users should download and apply that update from the vendor’s software download page. CISA also says affected systems shipped with VNC disabled by default, and VNC could only be enabled locally at the tower.
Broader defensive guidance
CISA recommends minimizing network exposure for control system devices, placing them behind firewalls, and separating them from business networks. When remote access is needed, it recommends using more secure methods such as VPNs, while noting that VPNs also need to be maintained carefully. CISA says no known public exploitation targeting this specific vulnerability has been reported at the time of publication.
Key points
- CISA flagged a critical flaw in Eppendorf BioFlo 320 bioreactors.
- The advisory says a hard-coded VNC password could enable remote takeover.
- Eppendorf says a software update removes VNC access from the controller.
- CISA recommends limiting network exposure and isolating control systems.
- No known public exploitation has been reported so far.



