device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and used to authenticate to device services.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Jinan USR IOT Technology Limited (PUSR) did not respond to CISA's attempts at coordination. Users of PUSR USR-W610 devices are encouraged to contact PUSR and keep their systems up to date.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jinan Usr Iot Technology Limited (pusr)
Jinan Usr Iot Technology Limited (pusr) usr-w610 Rs232/485 To Wi-fi/ethernet Converter |
|
| Vendors & Products |
Jinan Usr Iot Technology Limited (pusr)
Jinan Usr Iot Technology Limited (pusr) usr-w610 Rs232/485 To Wi-fi/ethernet Converter |
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and used to authenticate to device services. | |
| Title | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-05-29T19:31:38.170Z
Reserved: 2026-05-04T16:07:42.001Z
Link: CVE-2026-7786
Updated: 2026-05-29T19:31:31.968Z
Status : Deferred
Published: 2026-05-29T18:17:13.403
Modified: 2026-06-16T16:03:27.593
Link: CVE-2026-7786
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:18:20Z