CVE-2025-68719
8.8KAYSUS · KS-WR3600
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authenticated users to download configuration archives containing sensitive files, which may lead to total device compromise.
Executive summary
A critical configuration management vulnerability in KAYSUS KS-WR3600 routers allows authenticated attackers to extract sensitive system files and achieve full device compromise.
Vulnerability
This vulnerability involves an insecure configuration management process where any authenticated user can query a backup endpoint to download a configuration archive. The archive includes sensitive system files such as /etc/shadow, which can be leveraged for credential recovery and elevated system access.
Business impact
The potential for full device compromise poses a severe risk to organizational network integrity. Because the configuration archive contains sensitive authentication data, an attacker can gain administrative control over the router, facilitate lateral movement within the network, or intercept sensitive traffic. Given the CVSS score of 8.8, this flaw is categorized as high severity and requires immediate attention to prevent unauthorized access to critical network infrastructure.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict administrative access to the device management interface to only trusted internal IP addresses.
Proactive Monitoring: Monitor device access logs for unusual backup requests or unexpected authenticated session activity.
Compensating Controls: Implement strict network segmentation to isolate these routers from sensitive internal segments and deploy a Web Application Firewall to block unauthorized access to the configuration backup endpoint if accessible via the network.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced in the CVE record.
Analyst recommendation
The severity of this vulnerability, combined with the availability of technical details for exploitation, necessitates immediate defensive action. Organizations utilizing KAYSUS KS-WR3600 routers must restrict management interfaces and monitor for unauthorized configuration backup requests while awaiting a vendor-supplied firmware update.