CVE-2025-62777: High severity Mikrotik MZK-DP300N vulnerability
Published Oct 28, 2025
·Updated
Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to the affected device via Telnet and execute arbitrary commands.
Affected Software
1 affected component
Mikrotik MZK-DP300N<1.07
Event History
Oct 28, 2025
CVE Published
via MITRE·04:53 AM
Data Sourced
via MITRE·04:53 AM
DescriptionSeverity
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62777?
CVE-2025-62777 is considered a medium severity vulnerability as it allows local attackers to gain unauthorized access to the device.
2
How do I fix CVE-2025-62777?
To fix CVE-2025-62777, update the Mikrotik MZK-DP300N device to a version later than 1.07 to eliminate hard-coded credentials.
3
What systems are affected by CVE-2025-62777?
CVE-2025-62777 affects Mikrotik MZK-DP300N versions 1.07 and earlier.
4
Can CVE-2025-62777 be exploited remotely?
CVE-2025-62777 can only be exploited by attackers within the same local network.
5
What are the potential consequences of CVE-2025-62777?
If exploited, CVE-2025-62777 allows attackers to execute arbitrary commands on the affected device.