CVE-2025-7881: Mercusys MW301R Web Interface password recovery
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument code leads to weak password recovery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7881?
CVE-2025-7881 has been declared as problematic due to its impact on the web interface of the Mercusys MW301R.
How does CVE-2025-7881 affect password recovery?
CVE-2025-7881 leads to weak password recovery mechanisms that can be manipulated by attackers.
What component is affected by CVE-2025-7881?
CVE-2025-7881 affects the web interface of the Mercusys MW301R router.
What kind of attack can be initiated through CVE-2025-7881?
An attacker can exploit CVE-2025-7881 to manipulate argument code, which may allow unauthorized access.
Is there a known fix for CVE-2025-7881?
Currently, no specific fix has been provided for CVE-2025-7881, and users should monitor for updates from Mercusys.