CVE-2026-82487
Received Received - Intake

Weak Password Recovery in Beetel 450TC3 Router

Vulnerability report for CVE-2026-82487, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulDB

Description

A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
beetel 450tc3 01.00.00_01

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Beetel 450TC3 router allows an authenticated user with low privileges to reset the administrator password without knowing the current password. By exploiting an authorization flaw in the web management interface, the attacker can modify their password change request to target the admin account, gaining full administrative access to the device.

Detection Guidance

To detect this vulnerability, check if your Beetel 450TC3 router is running firmware version V01.00.00_01. Inspect network traffic for unauthorized password reset requests or unusual administrative changes. Monitor logs for repeated failed login attempts or unexpected account modifications.

Impact Analysis

An attacker could gain full control over your router, allowing them to change configurations, alter firewall and DNS settings, manage user accounts, and intercept network traffic. This could lead to unauthorized access to your network, data breaches, or further attacks on connected devices.

Compliance Impact

This vulnerability allows unauthorized users to gain full administrative access to the router, potentially exposing sensitive network traffic, user data, and system configurations. For GDPR, this could lead to unauthorized access to personal data, violating data protection requirements. For HIPAA, it may compromise protected health information if the router is used in healthcare environments.

Mitigation Strategies

Immediately update the router firmware to the latest version if available. Disable remote administration if not required. Restrict access to the web management interface to trusted networks only. Change all router passwords using a secure method and enable multi-factor authentication if supported.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82487. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart