CVE-2025-65010 describes a Broken Access Control vulnerability in the WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28), specifically within its initial configuration wizard.cgi endpoint. This flaw allows an unauthenticated attacker on the local network to change the administrative password without authorization, even after initial setup. With a CVSS v4.0 score of 7.1 (HIGH), the vulnerability has a low attack complexity and can lead to high integrity impact, as an attacker can gain full control over the device. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| WODESYS | WD-R608U | WDR28081123OV1.01CNA affecteddefault unknown | |
| WODESYS | WDR122B V2.0 | WDR28081123OV1.01CNA affecteddefault unknown | |
| WODESYS | WDR28 | WDR28081123OV1.01CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.