PT-2026-1918 · Kaysus · Kaysus Ks-Wr3600

Published

2026-01-08

·

Updated

2026-02-02

·

CVE-2025-68716

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KAYSUS KS-WR3600 version 1.0.5.9.1
Description KAYSUS KS-WR3600 routers with firmware version 1.0.5.9.1 have the SSH service enabled by default on the LAN interface. The root account is configured without a password, and administrators are unable to disable SSH or enforce authentication through the command-line interface or web graphical user interface. This allows a local area network attacker to easily gain root shell access and execute arbitrary commands with full privileges.
Recommendations For KAYSUS KS-WR3600 version 1.0.5.9.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-68716

Affected Products

Kaysus Ks-Wr3600