CVE-2025-63423

7.5

Each Italy · Wireless Mini Router WIRELESS-N 300M

The Each Italy Wireless Mini Router WIRELESS-N 300M stores the administrator password in plain text, potentially allowing unauthorized access to device management.

Executive summary

The Each Italy Wireless Mini Router WIRELESS-N 300M is vulnerable to insecure credential storage, which poses a significant risk of unauthorized administrative access.

Vulnerability

This vulnerability involves the insecure storage of the administrator password within the device firmware. The CVSS vector indicates that this flaw is remotely exploitable without authentication or user interaction.

Business impact

The exposure of administrative credentials allows an attacker to gain full control over the router. This compromise could lead to unauthorized network traffic interception, man in the middle attacks, or the complete redirection of internal traffic, justifying the High severity CVSS score of 7.5.

Remediation

Immediate Action: Since no official patch is currently available, administrators should restrict management interface access to trusted internal IP addresses only.

Proactive Monitoring: Review device logs for unauthorized login attempts or unexpected configuration changes that may indicate the use of stolen credentials.

Compensating Controls: Implement network segmentation to isolate the management interface from the public internet and use a hardware firewall to block unauthorized access to the device management ports.

Exploitation status

Public Exploit Available: Yes, a public proof of concept exists, as documented in the security advisory referenced on GitHub.

Analyst recommendation

Given the lack of a vendor-provided patch, users must treat this device as inherently insecure for sensitive environments. Immediately isolate the device from external network exposure and monitor for any anomalous administrative activity until the vendor provides a firmware update to address the credential storage mechanism.

Sources