Back to CVE List

CVE-2026-25715

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

The web management interface of the device allows the administrator
username and password to be set to blank values. Once applied, the
device permits authentication with empty credentials over the web
management interface and Telnet service. This effectively disables
authentication across all critical management channels, allowing any
network-adjacent attacker to gain full administrative control without
credentials.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-521
Source
NVD
Vendor
Jinan USR IOT Technology Limited (PUSR)
Product
USR-W610

External References

Discussion (0)

Add Comment

No comments yet. Be the first!