CVE-2025-62775
8.0Mercku · M6a
Mercku M6a devices through version 2.1.0 contain a vulnerability that allows root access via TELNET using the web administrative password.
Executive summary
A critical vulnerability in Mercku M6a devices allows authenticated attackers to gain unauthorized root-level access via TELNET, posing a severe risk of complete system compromise.
Vulnerability
This issue involves incorrect resource transfer between spheres (CWE-669), where the web administrative password is accepted for root TELNET authentication. The vulnerability requires the attacker to have low-level privileges or network access to the management interface.
Business impact
The ability for an attacker to gain root access on network infrastructure devices carries extreme risk, including full control over traffic, data interception, and persistence within the local network. With a CVSS score of 8.0, this high-severity flaw threatens the confidentiality, integrity, and availability of all data traversing the affected hardware, potentially leading to widespread operational disruption.
Remediation
Immediate Action: Restrict access to the TELNET interface and the web management portal to trusted administrative networks only until a firmware patch is released by the vendor.
Proactive Monitoring: Monitor device logs for unauthorized TELNET connection attempts and anomalous administrative login patterns.
Compensating Controls: Implement strict network segmentation to isolate affected devices and utilize firewall rules to block external access to management ports.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the technical write-up referenced in the security disclosures.
Analyst recommendation
Given the high-severity nature of this vulnerability and the availability of proof-of-concept information, organizations should treat this with high priority. Administrators must immediately restrict management interfaces from untrusted segments and monitor for vendor updates to address the underlying authentication flaw.