Default Credentials Vulnerability in Seeedstudio ReSpeaker LinkIt7688
CVE-2025-9576
Key Information:
- Vendor
Seeedstudio
- Status
- Vendor
- CVE Published:
- 28 August 2025
Badges
What is CVE-2025-9576?
A vulnerability has been identified in the administrative interface of Seeedstudio's ReSpeaker LinkIt7688 related to the use of default credentials stored in the /etc/shadow file. This issue allows local attackers to manipulate access settings and gain potential unauthorized access. The exploitability of this vulnerability requires a significant degree of complexity, demanding a knowledgeable attacker who can navigate the system environment. Publicly available exploits suggest that the risk remains present, despite the vendor being notified of the vulnerability without any response.
Affected Version(s)
ReSpeaker LinkIt7688
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved