CVE-2026-1407 is an information disclosure vulnerability affecting Beetel 777VR1 devices running firmware versions up to 01.00.09/01.00.09_55, specifically within an unknown part of its UART Interface. This vulnerability has a CVSS score of 4.2 (MEDIUM), indicating a physical attack vector with high complexity, requiring direct device access to extract sensitive information. While public exploit code exists, its exploitability is difficult, and there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage. The vendor has not responded to disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 01.00.09_55CPE matchmatch criteria | cpe:2.3:o:beetel:777vr1_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.