CVE-2025-68716

8.4

KAYSUS · KS-WR3600 Router

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 contain an insecure default configuration where the root account has no password, allowing unauthenticated remote access via SSH.

Executive summary

The KAYSUS KS-WR3600 router contains a critical vulnerability due to a default, password-less root account, enabling unauthenticated attackers to achieve full system control.

Vulnerability

The device ships with an SSH service enabled by default on the LAN interface and a root account configured with no password. This flaw allows any LAN-adjacent, unauthenticated attacker to obtain a root shell and execute arbitrary commands with full administrative privileges.

Business impact

A successful exploit grants an attacker full root access to the network infrastructure, leading to total compromise of the device. This allows for persistent unauthorized access to the local network, traffic interception, and potential disruption of critical business communications, justifying the high CVSS score of 8.4.

Remediation

Immediate Action: Since a patch is not currently available, administrators should immediately disable the device or restrict access to the LAN interface to trusted devices only. If possible, place the management interface on a dedicated, isolated management VLAN.

Proactive Monitoring: Monitor network traffic for unexpected SSH connections originating from unknown devices on the local area network. Review device logs for unauthorized login attempts or unexpected command execution.

Compensating Controls: Implement strict network access control lists to block SSH traffic (port 22) from unauthorized segments of the network. If the router supports it, disable the SSH service entirely via the configuration interface to remove the attack vector.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists via the technical write-up referenced on GitHub.

Analyst recommendation

Given the trivial nature of this exploit and the high level of access granted, immediate mitigation is required to protect the network perimeter. Organizations utilizing these routers must prioritize isolating these devices from their production environment until a firmware update is released by the manufacturer.

More KAYSUS CVEs

Sources