CVE-2025-9725 describes a hard-coded password vulnerability in the Cudy LT500E router, specifically affecting firmware versions up to 2.3.12, where a default 'admin' password was present in the /squashfs-root/etc/shadow file. This flaw carries a CVSS score of 8.8 (HIGH) due to its potential for complete compromise (Confidentiality, Integrity, Availability) if an attacker gains local access to the web interface. While the attack complexity is rated high and exploitability difficult, public exploit code is available, though there is no evidence of active exploitation, Metasploit/Nuclei modules, or significant community discussion. Cudy has addressed this in firmware version 2.3.13, which removes the default password and requires users to set a new one upon initial login.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.13CPE matchmatch criteria | cpe:2.3:o:cudy:lt500e_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.