Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 1.00.27
affected
Default status
unaffected
Any version before 1.00.67
affected
Description
The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an unauthenticated remote attacker could use to execute commands with root privileges. This vulnerability has been fixed in firmware version: 1.00.67 for CG3000TC and 1.00.27 for CG3000T.
Problem types
CWE-798 Use of Hard-coded Credentials
Product status
Any version before 1.00.27
Any version before 1.00.67
Credits
Piotr Ługowski
References
cert.pl/posts/2026/01/CVE-2025-7072/