CVE-2025-6560: Sapido Wireless Router - Exposure of Sensitive Information
Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.
The affected models are out of support; replacing the device is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Replace the out-of-support Sapido wireless router device models affected by the 'Exposure of Sensitive Information' issue, as recommended in the advisory.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6560?
CVE-2025-6560 has been classified as a high severity vulnerability due to the potential exposure of sensitive administrator credentials.
How do I fix CVE-2025-6560?
The best way to mitigate CVE-2025-6560 is to replace or upgrade affected Sapido wireless router models as they are no longer supported.
What are the risks associated with CVE-2025-6560?
Risks associated with CVE-2025-6560 include unauthorized access to administrative functions and potential takeover of the wireless router.
Which devices are affected by CVE-2025-6560?
CVE-2025-6560 affects multiple models of Sapido wireless routers that have been confirmed to be out of support.
Can CVE-2025-6560 be exploited remotely?
Yes, CVE-2025-6560 can be exploited remotely by unauthenticated attackers who can access sensitive configuration files.