CVE-2025-56463: Infoleak
Published Sep 26, 2025
·Updated
Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.
Affected Software
3 affected components
MERCUSYS MW305R<3.30
All of the following
MERCUSYS Mw305r Firmware<=3.30
MERCUSYS MW305R
Event History
Sep 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56463?
CVE-2025-56463 is considered a high severity vulnerability due to the exposure of the TLS certificate private key.
2
How do I fix CVE-2025-56463?
To fix CVE-2025-56463, update the Mercusys MW305R firmware to version 3.31 or later.
3
What is the impact of CVE-2025-56463?
The impact of CVE-2025-56463 includes potential man-in-the-middle attacks due to the disclosure of the TLS private key.
4
Which versions of Mercusys MW305R are affected by CVE-2025-56463?
Mercusys MW305R versions 3.30 and below are affected by CVE-2025-56463.
5
Is there a workaround for CVE-2025-56463 until the firmware is updated?
Currently, there are no known workarounds for CVE-2025-56463, and updating the firmware is strongly recommended.