CVE-2025-6529
BaseFortify
Publication date: 2025-06-23
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| 70mai | m300_firmware | to 2025-06-11 (inc) |
| 70mai | m300 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1392 | The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects the 70mai M300 device's Telnet Service component, allowing an attacker within the local network to exploit the use of default credentials. This means an attacker can gain unauthorized access by using preset usernames and passwords that have not been changed, potentially compromising the device.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to the affected device via Telnet, allowing attackers to potentially control or manipulate the device. This can result in data breaches, loss of device integrity, and disruption of services, especially since the exploit is publicly known and can be executed without user interaction.