All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request.
History

Mon, 29 Sep 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dingtian-tech dt-r002 Firmware
CPEs cpe:2.3:h:dingtian-tech:dt-r002:-:*:*:*:*:*:*:*
cpe:2.3:o:dingtian-tech:dt-r002_firmware:-:*:*:*:*:*:*:*
Vendors & Products Dingtian-tech dt-r002 Firmware
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Fri, 26 Sep 2025 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Dingtian-tech
Dingtian-tech dt-r002
Vendors & Products Dingtian-tech
Dingtian-tech dt-r002

Thu, 25 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 25 Sep 2025 17:00:00 +0000

Type Values Removed Values Added
Description All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request.

Thu, 25 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
Description All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request
Title Insufficiently Protected Credentials in Dingtian DT-R002
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-09-25T16:32:17.981Z

Updated: 2025-09-25T18:07:06.076Z

Reserved: 2025-09-23T15:29:33.138Z

Link: CVE-2025-10880

cve-icon Vulnrichment

Updated: 2025-09-25T18:01:21.757Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-25T17:15:38.090

Modified: 2025-09-29T14:44:22.307

Link: CVE-2025-10880

cve-icon Redhat

No data.