First published: Wed Apr 23 2025(Updated: )
BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25894.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
BEC Technologies Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2771 is considered critical due to its ability to allow remote attackers to bypass authentication on affected BEC Technologies routers.
To fix CVE-2025-2771, it is recommended to update your BEC Technologies router firmware to the latest version provided by the vendor.
CVE-2025-2771 affects multiple models of BEC Technologies routers that utilize the vulnerable authentication mechanism.
Yes, CVE-2025-2771 can be exploited remotely as it does not require authentication for exploitation.
The potential impacts of CVE-2025-2771 include unauthorized access to the router’s configuration and network exposure to attackers.