First published: Wed Apr 23 2025(Updated: )
BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from storing credentials in a recoverable format. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25986.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
BEC Technologies Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2770 is considered a moderate severity vulnerability due to its potential for sensitive information disclosure.
To mitigate CVE-2025-2770, ensure that firmware on BEC Technologies routers is updated to the latest version that addresses this vulnerability.
CVE-2025-2770 exploits cleartext password storage in BEC Technologies routers, allowing unauthorized information disclosure.
CVE-2025-2770 affects users of multiple BEC Technologies routers where authentication is required to access sensitive information.
Yes, CVE-2025-2770 can be exploited remotely by authenticated attackers to disclose sensitive information.