CVE-2025-8731 is a critical vulnerability affecting TRENDnet TI-G160i, TI-PG102i, and TPL-430AP devices up to firmware version 20250724, allowing remote attackers to exploit default SSH credentials. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network without user interaction, leading to complete compromise of confidentiality, integrity, and availability. While the vendor states default remote management is disabled and passwords are encrypted or user-set, public exploit disclosure and significant community discussion (11 mentions) indicate a high potential for exploitation, despite the "doubted" existence and lack of confirmed active exploitation or KEV listing.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| TRENDnet | TI-G160i | 20250724CNA affected | |
| TRENDnet | TI-PG102i | 20250724CNA affected | |
| TRENDnet | TPL-430AP | 20250724CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.