Kaysus develops a focused line of wireless routers and networking appliances, with its vulnerability footprint concentrated in products such as the KS-WR3600 and KS-WR1200 series. The recurring signal centers on authentication and access-control weaknesses—including missing or improper authentication, exposure of sensitive information, and inadequate file-system protection—characteristic of embedded network device firmware. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaysus over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68717CRITICAL KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unau | Jan 8, 2026 | 9.4 | 31 | NO | NO |
CVE-2025-68719HIGH KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and maintains an active session, an attacker can directly query the | Jan 8, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-68716HIGH KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no password, and administrators | Jan 8, 2026 | 8.4 | 27 | NO | NO |
CVE-2025-68718MEDIUM KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root credentials (root:12345678). The administrator cannot disable the | Jan 8, 2026 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaysus.
Media articles that mention a CVE ID that affects a product developed by Kaysus — matched by CVE ID, not by vendor name.