nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-2766 CVE-2025-2766
HIGH
70mai A510 Use of Default Password Authentication Bypass Vulnerability
Record summary
CVE-2025-2766 has a selected CVSS score of 8.8 (high).
Description
70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of 70mai A510. Authentication is not required to exploit this vulnerability. The specific flaw exists within the default configuration of user accounts. The configuration contains default password. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of the root. Was ZDI-CAN-24996.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 9, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | v1.0.40ww.2024.04.19 | affected |
References
2ZDI-25-180x_research advisory
https://www.zerodayinitiative.com/advisories/ZDI-25-180