IoT & Hardware

Information Disclosure

Cleartext Transmission of Administrator Credentials via HTTP Basic Authentication on Waveshare RS232/485 TO WIFI ETH (B)

Intercepted credentials enable remote administrative access.

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS92
PUBLISHED
2025-11-12
CVE IDs
CVE-2025-63364
VENDORS
Waveshare Electronics
PUBLIC EXPLOIT
PoC public
CWE
CWE-319
PRODUCT
RS232/485 TO WIFI ETH (B)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Cleartext Transmission of Credentials / Unprotected Transport:

Credentials are transmitted via HTTP Basic Authentication in plaintext over unencrypted HTTP.

The embedded web interface of the Waveshare Industrial-grade Serial Server-to-Wi-Fi gateway devices uses HTTP Basic Authentication over plaintext HTTP. Administrator credentials are transmitted as Base64-encoded strings within the Authorization header. Base64 is an encoding method, not encryption, and can be trivially decoded by an attacker monitoring network traffic.

The device does not offer HTTPS/TLS support, exposing user credentials to passive interception by any attacker on the same network. This leads to direct compromise of authentication, confidentiality, and enables unauthorized access to sensitive OT configuration interfaces.

This behavior violates secure transport principles and exposes administrative operations in ICS environments to interception, credential theft, and unauthorized system reconfiguration.

Vulnerability details

Vulnerability details

CVE-2025-63364
CWE-319
High | 7.5

Cleartext Transmission of Credentials / Unprotected Transport: Credentials are transmitted via HTTP Basic Authentication in plaintext over unencrypted HTTP.

Auth:
None (remote)
Impact:
Sensitive data disclosure
Impact

What an attacker can do

Intercepted credentials enable remote administrative access.

DISCLOSURE

Disclosure timeline

2025-09-16 Initial report sent via Waveshare support portal with full disclosure report.

2025-09-23 Vendor acknowledged receipt.

2025-09-23 Researcher requested remediation timeline, CVD process, and CVE coordination details.

2025-09-24 Vendor replied: "Information received; feedback will be taken into account in future research."

2025-09-24 Researcher requested confirmation on CVD process and timeline.

2025-09-27 Vendor responded: "No specific timeline can be provided; security feedback will be considered in subsequent products."

2025-09-27 Researcher informed

References

Credits

Abhishek Pandey – Payatu Security Consulting Pvt. Ltd.