IoT & Hardware
Information Disclosure
Administrator Password Displayed in Plaintext on Waveshare RS232/485 TO WIFI ETH (B)
Exposes valid administrator credentials, enabling device compromise.
.png)
Overview
Insufficiently Protected Credentials / UI Exposure of Secrets: Web Management Interface (M2M Web Server) Displays Administrator Password in Plaintext Input Field.
The web interface of the Waveshare RS232/485 TO WIFI ETH (B) Serial-to-Ethernet/Wi-Fi Gateway (Firmware V3.1.1.0, HW 4.3.2.1, Webpage V7.04T.07.002880.0301) displays the administrator password in plaintext.
The password field (SYSPS) is rendered as <input type="text">, allowing anyone with web access or developer-tool visibility to read credentials
Vulnerability details
Insufficiently Protected Credentials / UI Exposure of Secrets: Web Management Interface (M2M Web Server) Displays Administrator Password in Plaintext Input Field.
What an attacker can do
Exposes valid administrator credentials, enabling device compromise.
Disclosure timeline
2025-09-16 Initial report sent via Waveshare support portal with full disclosure report.
2025-09-23 Vendor acknowledged receipt.
2025-09-23 Researcher requested remediation timeline, CVD process, and CVE coordination details.
2025-09-24 Vendor replied: "Information received; feedback will be taken into account in future research."
2025-09-24 Researcher requested confirmation on CVD process and timeline.
2025-09-27 Vendor responded: "No specific timeline can be provided; security feedback will be considered in subsequent products."
2025-09-27 Researcher informed
References
2026-06-17 (NVD record)
Credits
Abhishek Pandey – Payatu Security Consulting Pvt. Ltd.
















