CVE-2025-65007: Missing Authentication for Critical Function in WODESYS WD-R608U router
In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration change module in the adm.cgi endpoint, the unauthenticated attacker can execute commands including backup creation, device restart and resetting the device to factory settings.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version WDR28081123OV1.01 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65007?
CVE-2025-65007 is classified as a high severity vulnerability due to the potential for unauthenticated remote command execution.
What devices are affected by CVE-2025-65007?
CVE-2025-65007 affects the WODESYS WD-R608U, WDR122B V2.0, and WDR28 routers.
How do I fix CVE-2025-65007?
To mitigate CVE-2025-65007, it is recommended to disable remote management and ensure that firmware is updated to the latest version provided by the vendor.
Can CVE-2025-65007 allow an attacker to control the device?
Yes, CVE-2025-65007 allows an attacker to execute commands on the device without authentication, potentially leading to complete control over it.
What are the potential impacts of CVE-2025-65007?
The potential impacts of CVE-2025-65007 include unauthorized device backups, restarts, and factory resets.