CVE-2025-43982
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
13/08/2025
Last modified:
14/08/2025
Description
Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that cannot be disabled in the GUI.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



