IoT & Hardware
Information Disclosure
Cleartext Transmission of Administrator Credentials via HTTP Basic Authentication on Waveshare RS232/485 TO WIFI ETH (B)
Intercepted credentials enable remote administrative access.
.png)
Overview
Cleartext Transmission of Credentials / Unprotected Transport:
Credentials are transmitted via HTTP Basic Authentication in plaintext over unencrypted HTTP.
The embedded web interface of the Waveshare Industrial-grade Serial Server-to-Wi-Fi gateway devices uses HTTP Basic Authentication over plaintext HTTP. Administrator credentials are transmitted as Base64-encoded strings within the Authorization header. Base64 is an encoding method, not encryption, and can be trivially decoded by an attacker monitoring network traffic.
The device does not offer HTTPS/TLS support, exposing user credentials to passive interception by any attacker on the same network. This leads to direct compromise of authentication, confidentiality, and enables unauthorized access to sensitive OT configuration interfaces.
This behavior violates secure transport principles and exposes administrative operations in ICS environments to interception, credential theft, and unauthorized system reconfiguration.
Vulnerability details
Cleartext Transmission of Credentials / Unprotected Transport: Credentials are transmitted via HTTP Basic Authentication in plaintext over unencrypted HTTP.
What an attacker can do
Intercepted credentials enable remote administrative access.
Disclosure timeline
2025-09-16 Initial report sent via Waveshare support portal with full disclosure report.
2025-09-23 Vendor acknowledged receipt.
2025-09-23 Researcher requested remediation timeline, CVD process, and CVE coordination details.
2025-09-24 Vendor replied: "Information received; feedback will be taken into account in future research."
2025-09-24 Researcher requested confirmation on CVD process and timeline.
2025-09-27 Vendor responded: "No specific timeline can be provided; security feedback will be considered in subsequent products."
2025-09-27 Researcher informed
References
2026-06-17 (NVD record)
Credits
Abhishek Pandey – Payatu Security Consulting Pvt. Ltd.
















