CVE-2026-2616: Beetel 777VR1 Web Management hard-coded credentials
A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is advisable to modify the configuration settings. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2616?
CVE-2026-2616 has a high severity due to the presence of hard-coded credentials that can be exploited by attackers.
How do I fix CVE-2026-2616?
To fix CVE-2026-2616, you should upgrade the Beetel 777VR1 web management interface to a version beyond 01.00.09.
What systems are affected by CVE-2026-2616?
CVE-2026-2616 affects the Beetel 777VR1 devices running versions up to and including 01.00.09.
What can an attacker achieve with CVE-2026-2616?
An attacker can gain unauthorized access to the Beetel 777VR1 web management interface due to hard-coded credentials.
Is there a workaround for CVE-2026-2616 if I cannot update immediately?
If an immediate update cannot be performed, restricting network access to the Beetel 777VR1 management interface can serve as a temporary workaround.