Insufficiently Protected Credentials in Dingtian DT-R002 from Dingtian
CVE-2025-10879

8.7HIGH

Key Information:

Vendor

Dingtian

Status
Vendor
CVE Published:
25 September 2025

What is CVE-2025-10879?

The Dingtian DT-R002 device reveals a vulnerability that allows unauthorized attackers to obtain the current user's username without any authentication. This flaw arises from insufficiently protected credentials, potentially exposing sensitive user information and raising significant security concerns. Organizations utilizing this product should prioritize addressing this vulnerability to safeguard their data integrity.

Affected Version(s)

DT-R002 All versions

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nicolas Cano and Reid Wightman of Dragos
.
CVE-2025-10879 : Insufficiently Protected Credentials in Dingtian DT-R002 from Dingtian