CRITICAL🇵🇱 Wersja polska

CVE-2025-6560

CVSS 9.3v4.0pub. 2025-06-24upd. 2026-04-15

Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.  The affected models are out of support; replacing the device is recommended.

🤖 AI Analysis
How it works

An attacker can directly access the device configuration file without authentication via the network. This file contains administrator authentication credentials stored in plaintext, which violates secure password storage principles (CWE-256 — Plaintext Storage of a Password). Once this data is obtained, the attacker can take full control of the device.

Impact

An attacker gains access to router administrator credentials in plaintext, enabling complete device takeover, network configuration modification, network traffic interception, or use of the router as an entry point for further attacks on the internal network.

Mitigation & patch

The manufacturer does not plan to release a patch — the indicated models are end-of-life and out of support cycle. The manufacturer recommends replacing devices with new, actively supported models. Until replacement, access to the device management interface should be restricted to trusted hosts only, and the device should be isolated from unauthenticated external access.

Who is affected

Multiple models of Sapido wireless routers — specific models indicated in the manufacturer's references (TWCERT). All listed models are no longer supported by the manufacturer.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References