CVE-2025-62777

8.8

PLANEX COMMUNICATIONS INC. · MZK-DP300N

A hard-coded credentials vulnerability in PLANEX MZK-DP300N allows unauthenticated local network attackers to gain Telnet access and execute arbitrary commands.

Executive summary

The PLANEX MZK-DP300N router contains hard-coded credentials that enable unauthorized command execution by local network attackers, posing a severe risk to device integrity.

Vulnerability

This vulnerability involves the use of hard-coded credentials within the device firmware, which permits an unauthenticated attacker on the local network to gain administrative access via Telnet and execute arbitrary system commands.

Business impact

Successful exploitation allows an attacker to gain full control over the affected network device, potentially leading to unauthorized network traffic interception, pivot points for lateral movement, or complete denial of service. With a CVSS score of 8.8, this vulnerability represents a high risk to the confidentiality, integrity, and availability of local network infrastructure.

Remediation

Immediate Action: Since a direct patch is currently unknown, users should immediately restrict access to the Telnet interface or isolate the device from untrusted network segments.

Proactive Monitoring: Monitor network traffic for unauthorized Telnet connections and review device logs for anomalous command execution patterns.

Compensating Controls: Implement strict network segmentation and firewall rules to prevent unauthorized hosts from accessing the device management interfaces.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity of this vulnerability, immediate mitigation is necessary to protect the internal network from potential compromise. Administrators should prioritize isolating vulnerable devices and contact the vendor for further guidance on available firmware updates or security workarounds.

Sources