CVE-2025-44643 describes an Insecure Configuration vulnerability in specific Draytek AP903, AP912C, and AP918R products, where a hardcoded weak password is set in the ripd.conf file. This vulnerability has a CVSS score of 8.6 (HIGH), indicating it can be exploited remotely with low complexity to achieve partial confidentiality and integrity, and complete availability impact. An attacker could exploit this to gain unauthorized control over the routing daemon, potentially altering network routes or intercepting traffic. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.