CVE-2025-65009 describes a critical vulnerability in the WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28), where the administrative password is stored in plaintext within the configuration file, allowing unauthorized access via direct resource references. This vulnerability carries a CVSS score of 7.1 (HIGH), indicating that an unauthenticated attacker on the adjacent network can easily exploit it to gain full control over the device, leading to a complete compromise of confidentiality. While only version WDR28081123OV1.01 has been confirmed vulnerable, other versions may also be affected. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| WODESYS | WD-R608U | WDR28081123OV1.01CNA affecteddefault unknown | |
| WODESYS | WDR122B V2.0 | WDR28081123OV1.01CNA affecteddefault unknown | |
| WODESYS | WDR28 | WDR28081123OV1.01CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.