CVE-2025-62771
7.5Mercku · M6a
Mercku M6a routers through firmware version 2.1.0 are vulnerable to Cross-Site Request Forgery (CSRF), allowing unauthenticated attackers to change device passwords.
Executive summary
A Cross-Site Request Forgery vulnerability in Mercku M6a devices allows unauthenticated attackers to modify administrative credentials, posing a significant risk to network security.
Vulnerability
This vulnerability is a Cross-Site Request Forgery (CWE-352) that allows an unauthenticated attacker to force a user to perform unwanted actions, specifically changing the administrative password of the device. The attack vector is restricted to the intranet (adjacent network), requiring the attacker to be positioned on the local network.
Business impact
Successful exploitation allows an unauthorized party to gain administrative control over the router by resetting its password. This could lead to a complete compromise of the local network, unauthorized access to sensitive traffic, and potential redirection of network communications. Given the CVSS score of 7.5, this high-severity flaw represents a significant risk to internal network integrity and confidentiality.
Remediation
Immediate Action: Since a specific patch version is currently unknown, users should immediately restrict access to the device management interface to trusted internal IP addresses only.
Proactive Monitoring: Review device access logs for unauthorized attempts to access the management interface or unusual administrative account modifications.
Compensating Controls: Disable remote management features on the router where possible, and ensure that all connected devices are protected by additional endpoint security to prevent local network traversal.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the technical write-up referenced at blog.nullvoid.me.
Analyst recommendation
Given the availability of a proof-of-concept and the high-severity impact of a credential takeover, administrators must treat this vulnerability with urgency. Immediately isolate the management interface from untrusted users and monitor for any vendor-issued firmware updates that address this CSRF flaw.