Sensitive Credential Exposure in TP-Link TL-WR740N Firmware by DD-WRT
CVE-2025-56565
7.6HIGH
What is CVE-2025-56565?
The DD-WRT firmware deployed on various versions of the TP-Link TL-WR740N exposes sensitive authentication credentials in cleartext stored within the device's non-volatile memory. This includes critical information such as SSH private keys, dynamic DNS passwords, email notification credentials, and administrative passwords. An attacker with physical access to the device can exploit this vulnerability by extracting these credentials from an SPI flash dump. This exploitation can lead to a complete compromise of the device, unauthorized infiltration of the connected network, and unauthorized access to third-party services relying on these credentials.