Description
This vulnerability exists in Digisol DG-GR6821AC Router due to storage of credentials and PINS without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the unencrypted data stored in the firmware of targeted device. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the network of the targeted device.
Problem types
CWE-312: Cleartext Storage of Sensitive Information
Product status
V3.2.XX
Credits
This vulnerability is reported by Shravan Singh from Kavach IoT Security.
References
www.cert-in.org.in/...eid=PUBVLNOTES01&VLCODE=CIVN-2025-0147