CVE-2026-24455

HIGH

Device Web Interface - Info Disclosure

Title source: llm
STIX 2.1

Description

The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 9.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (1)
Jinan USR IOT Technology Limited (PUSR)/USR-W610 < 3.1.1.0
Published Feb 20, 2026
Tracked Since Feb 21, 2026