# CVE-2026-25715

## Summary

- **CVE ID:** CVE-2026-25715
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-521
- **Published:** Feb 20, 2026
- **Last Modified:** Mar 12, 2026

## Description

The web management interface of the device allows the administrator 
username and password to be set to blank values. Once applied, the 
device permits authentication with empty credentials over the web 
management interface and Telnet service. This effectively disables 
authentication across all critical management channels, allowing any 
network-adjacent attacker to gain full administrative control without 
credentials.

## Affected Products

- Jinan USR IOT Technology Limited (PUSR) — USR-W610 (0)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-050-03)
- [CNA](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-050-03.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.57%
- **EPSS Percentile:** 45.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._