CVE Explorer
CVE-2025-65009
In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) admin password is stored in configuration file as plaintext and can be obtained by unauthorized user by direct references to the resource in question.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version WDR28081123OV1.01 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 3 assertions
{"defaultStatus":"unknown","product":"WD-R608U","vendor":"WODESYS","versions":[{"status":"affected","version":"WDR28081123OV1.01","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/affected/0
{"defaultStatus":"unknown","product":"WDR122B V2.0","vendor":"WODESYS","versions":[{"status":"affected","version":"WDR28081123OV1.01","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/affected/2
{"defaultStatus":"unknown","product":"WDR28","vendor":"WODESYS","versions":[{"status":"affected","version":"WDR28081123OV1.01","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/affected/1
Affected products and versions
3 source assertions{"defaultStatus":"unknown","product":"WD-R608U","vendor":"WODESYS","versions":[{"status":"affected","version":"WDR28081123OV1.01","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/affected/0
{"defaultStatus":"unknown","product":"WDR122B V2.0","vendor":"WODESYS","versions":[{"status":"affected","version":"WDR28081123OV1.01","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/affected/2
{"defaultStatus":"unknown","product":"WDR28","vendor":"WODESYS","versions":[{"status":"affected","version":"WDR28081123OV1.01","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NO…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-256","description":"CWE-256 Plaintext Storage of a Password","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["product"],"url":"http://www.wodesys.com/eproductms52.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/references/0
{"tags":["third-party-advisory"],"url":"https://cert.pl/en/posts/2025/12/CVE-2025-65007"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/wcyb/security_research"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2a8f74a990f067a270c192c568d0d64890c03b391d3a42e637ca9adfe21d2937 · sha256:1ad94994f8febaf1… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.