CVE-2025-65011

Severity CVSS v4.0:
HIGH
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
18/12/2025
Last modified:
19/12/2025

Description

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by directly referencing the resource in question.<br /> <br /> The vendor was notified early about this vulnerability, but didn&amp;#39;t respond with the details of vulnerability or vulnerable version range. Only version WDR28081123OV1.01 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.