CVE-2025-10879

All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to retrieve the current user's username without authentication.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-268-01 Mitigation US Government Resource Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dingtian-tech:dt-r002_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dingtian-tech:dt-r002:-:*:*:*:*:*:*:*

History

29 Sep 2025, 14:43

Type Values Removed Values Added
CPE cpe:2.3:h:dingtian-tech:dt-r002:-:*:*:*:*:*:*:*
cpe:2.3:o:dingtian-tech:dt-r002_firmware:*:*:*:*:*:*:*:*
References () https://www.cisa.gov/news-events/ics-advisories/icsa-25-268-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-25-268-01 - Mitigation, US Government Resource, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Dingtian-tech dt-r002
Dingtian-tech dt-r002 Firmware
Dingtian-tech

25 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-25 17:15

Updated : 2025-09-29 14:43


NVD link : CVE-2025-10879

Mitre link : CVE-2025-10879

CVE.ORG link : CVE-2025-10879


JSON object : View

Products Affected

dingtian-tech

  • dt-r002_firmware
  • dt-r002
CWE
CWE-522

Insufficiently Protected Credentials