IoT & Hardware

Information Disclosure

Administrator Password Displayed in Plaintext on Waveshare RS232/485 TO WIFI ETH (B)

Exposes valid administrator credentials, enabling device compromise.

5.7
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS90
PUBLISHED
2025-11-12
CVE IDs
CVE-2025-63361
VENDORS
Waveshare Electronics
PUBLIC EXPLOIT
PoC public
CWE
CWE-522
PRODUCT
RS232/485 TO WIFI ETH (B)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Insufficiently Protected Credentials / UI Exposure of Secrets: Web Management Interface (M2M Web Server) Displays Administrator Password in Plaintext Input Field.

The web interface of the Waveshare RS232/485 TO WIFI ETH (B) Serial-to-Ethernet/Wi-Fi Gateway (Firmware V3.1.1.0, HW 4.3.2.1, Webpage V7.04T.07.002880.0301) displays the administrator password in plaintext.

The password field (SYSPS) is rendered as <input type="text">, allowing anyone with web access or developer-tool visibility to read credentials

Vulnerability details

Vulnerability details

CVE-2025-63361
CWE-522
Medium | 5.7

Insufficiently Protected Credentials / UI Exposure of Secrets: Web Management Interface (M2M Web Server) Displays Administrator Password in Plaintext Input Field.

Auth:
Any authenticated user (remote, user interaction required)
Impact:
Sensitive data disclosure
Impact

What an attacker can do

Exposes valid administrator credentials, enabling device compromise.

DISCLOSURE

Disclosure timeline

2025-09-16 Initial report sent via Waveshare support portal with full disclosure report.

2025-09-23 Vendor acknowledged receipt.

2025-09-23 Researcher requested remediation timeline, CVD process, and CVE coordination details.

2025-09-24 Vendor replied: "Information received; feedback will be taken into account in future research."

2025-09-24 Researcher requested confirmation on CVD process and timeline.

2025-09-27 Vendor responded: "No specific timeline can be provided; security feedback will be considered in subsequent products."

2025-09-27 Researcher informed

References

Credits

Abhishek Pandey – Payatu Security Consulting Pvt. Ltd.