IoT & Hardware

Authentication & Access Bypass

Authentication Bypass via Blank Credentials in Waveshare RS232/485 TO WIFI ETH (B)

Unauthenticated attackers can fully control the device, alter network settings, and upload firmware.

9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS91
PUBLISHED
2025-11-12
CVE IDs
CVE-2025-63362
VENDORS
Waveshare Electronics
PUBLIC EXPLOIT
PoC public
CWE
CWE-620
PRODUCT
RS232/485 TO WIFI ETH (B)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Improper Authentication / Authentication Bypass:

Improper Authentication / Authentication Bypass :Device allows Administrator username and password to be set to blank values, disabling authentication on Web and Telnet interfaces.

The CGI handler /EN/do_cmd.html fails to validate the admuser and SYSPS parameters.

If both are left blank, the authentication check is bypassed, granting unauthenticated administrative access.

Vulnerability details

Vulnerability details

CVE-2025-63362
CWE-620
Critical | 9.8

Improper Authentication / Authentication Bypass: Improper Authentication / Authentication Bypass :Device allows Administrator username and password to be set to blank values, disabling authentication on Web and Telnet interfaces.

Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
Impact

What an attacker can do

Unauthenticated attackers can fully control the device, alter network settings, and upload firmware.

DISCLOSURE

Disclosure timeline

2025-09-16 Initial report sent via Waveshare support portal with full disclosure report.

2025-09-23 Vendor acknowledged receipt.

2025-09-23 Researcher requested remediation timeline, CVD process, and CVE coordination details.

2025-09-24 Vendor replied: "Information received; feedback will be taken into account in future research."

2025-09-24 Researcher requested confirmation on CVD process and timeline.

2025-09-27 Vendor responded: "No specific timeline can be provided; security feedback will be considered in subsequent products."

2025-09-27 Researcher informed

References

Credits

Abhishek Pandey – Payatu Security Consulting Pvt. Ltd.