news.mlab.sh
Back to the feed
vulnerability

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter

Critical
Summary

This advisory details a critical vulnerability in the Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter, specifically version 7.03T.07. The device contains hardcoded administrative credentials that can be extracted through firmware analysis, potentially granting attackers administrator access. This poses a significant risk to critical infrastructure and requires immediate remediation.

The vulnerability stems from the inclusion of plaintext administrative credentials directly within the firmware image of the USR-W610 converter. This allows attackers to bypass standard authentication mechanisms and gain unauthorized access to the device's services. The CISA advisory highlights the potential impact on critical manufacturing systems, emphasizing the need for proactive security measures. CISA recommends minimizing network exposure, isolating control systems behind firewalls, and utilizing secure remote access methods like VPNs, while acknowledging their own potential vulnerabilities. Organizations are urged to conduct thorough impact analysis and risk assessments before implementing any defensive strategies.

Read the full article at CISA Advisories