CVE-2025-8731: TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials
A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains: "For product TI-PG102i and TI-G160i, by default, the product's remote management options are all disabled. The root account is for troubleshooting purpose and the password is encrypted. However, we will remove the root account from the next firmware release. For product TPL-430AP, the initial setup process requires user to set the password for the management GUI. Once that was done, the default password will be invalid."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Upgrade to the next firmware release where the root account is removed, so default/legacy root access is no longer available.
TRENDnet TPL-430AP root account = removed (from next firmware release) - Compensating control
Since TI-PG102i and TI-G160i have remote management options disabled by default, keep remote management disabled (including any remotely accessible SSH service functionality) to reduce exposure to remotely initiated attacks.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8731?
CVE-2025-8731 is classified as a critical severity vulnerability.
How do I fix CVE-2025-8731?
To fix CVE-2025-8731, change the default credentials used by the SSH service on affected devices.
Which devices are affected by CVE-2025-8731?
CVE-2025-8731 affects TRENDnet TI-G160i, TI-PG102i, and TPL-430AP devices up to version 20250724.
What type of vulnerability is CVE-2025-8731?
CVE-2025-8731 is a vulnerability that allows the use of default credentials in the SSH service.
Can CVE-2025-8731 be exploited remotely?
Yes, CVE-2025-8731 can be exploited remotely due to its nature of allowing default credentials.