PT-2025-33067 · Unknown · Shenzhen Tuoshi Nr500-Ea+1
Published
2025-08-13
·
Updated
2025-08-14
·
CVE-2025-43982
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLIC version 3.4.2731.16.43
Description:
Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLIC devices enable the SSH service by default. A hidden, hard-coded root account exists that cannot be disabled through the graphical user interface.
Recommendations:
Disable the SSH service on affected devices.
Change the default hard-coded root password, if possible, through alternative methods not available in the GUI.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rg500Ueaabxcomslic
Shenzhen Tuoshi Nr500-Ea