7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
The embedded web interface of the device does not support HTTPS/TLS for
authentication and uses HTTP Basic Authentication. Traffic is encoded
but not encrypted, exposing user credentials to passive interception by
attackers on the same network.
authentication and uses HTTP Basic Authentication. Traffic is encoded
but not encrypted, exposing user credentials to passive interception by
attackers on the same network.
Basic Information
ID
CVE-2026-24455
Source
icscert
Published
Feb 20, 2026 at 16:00
Affected Product
Vendor
Jinan USR IOT Technology Limited (PUSR)
Product
USR-W610
Affected Versions
Jinan USR IOT Technology Limited (PUSR) USR-W610 0