CVE-2026-25715
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/02/2026
Last modified:
20/02/2026
Description
The web management interface of the device allows the administrator <br />
username and password to be set to blank values. Once applied, the <br />
device permits authentication with empty credentials over the web <br />
management interface and Telnet service. This effectively disables <br />
authentication across all critical management channels, allowing any <br />
network-adjacent attacker to gain full administrative control without <br />
credentials.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



