CVE-2026-2616 is a critical vulnerability affecting the Beetel 777VR1 router firmware up to version 01.00.09, specifically within its Web Management Interface, due to hard-coded credentials. With a CVSS score of 9.8, this vulnerability allows an unauthenticated attacker on the local network to achieve full compromise (confidentiality, integrity, availability). While there is no evidence of active exploitation or public exploit code on common platforms, the exploit has been publicly disclosed, and the vulnerability has garnered significant community discussion, indicating potential for future exploitation. Users are strongly advised to modify configuration settings as the vendor has not responded to disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 01.00.09_55CPE matchmatch criteria | cpe:2.3:o:beetel:777vr1_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.