PT-2026-1918 · Kaysus · Kaysus Ks-Wr3600
Published
2026-01-08
·
Updated
2026-02-02
·
CVE-2025-68716
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
KAYSUS KS-WR3600 version 1.0.5.9.1
Description
KAYSUS KS-WR3600 routers with firmware version 1.0.5.9.1 have the SSH service enabled by default on the LAN interface. The root account is configured without a password, and administrators are unable to disable SSH or enforce authentication through the command-line interface or web graphical user interface. This allows a local area network attacker to easily gain root shell access and execute arbitrary commands with full privileges.
Recommendations
For KAYSUS KS-WR3600 version 1.0.5.9.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kaysus Ks-Wr3600