Insufficiently Protected Credentials Vulnerability in Dingtian DT-R002 Product
CVE-2025-10880

8.7HIGH

Key Information:

Vendor

Dingtian

Status
Vendor
CVE Published:
25 September 2025

What is CVE-2025-10880?

The Dingtian DT-R002 product is affected by a severe vulnerability that exposes insufficiently protected credentials. This flaw allows attackers to exploit the system through unauthenticated GET requests, enabling them to extract sensitive protocol passwords associated with the proprietary 'Dingtian Binary' protocol. Organizations using this product should take immediate action to secure their systems against potential exploitation and protect their sensitive data.

Affected Version(s)

DT-R002 All versions

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nicolas Cano and Reid Wightman of Dragos
.
CVE-2025-10880 : Insufficiently Protected Credentials Vulnerability in Dingtian DT-R002 Product