CVE Vulnerabilities

CVE-2025-10880

Insufficiently Protected Credentials

Published: Sep 25, 2025 | Modified: Sep 29, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary Dingtian Binary protocol password by sending an unauthenticated GET request.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Dt-r002_firmware Dingtian-tech - (including) - (including)

Potential Mitigations

References