Cyber Posture

CVE-2025-1283

Critical

Published: 13 February 2025

Published
13 February 2025
Modified
10 April 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0003 7.1th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page.

Security Summary

CVE-2025-1283, published on 2025-02-13, is a critical vulnerability in the Dingtian DT-R0 Series that enables attackers to bypass login requirements by directly navigating to the main page. This authentication bypass issue, linked to CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and CWE-306 (Missing Authentication for Critical Function), carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its network accessibility and potential for significant impact.

The vulnerability can be exploited by unauthenticated remote attackers with network access to the affected device, requiring low complexity and no user interaction. Successful exploitation allows bypassing authentication controls, granting direct access to the main page and potentially leading to high confidentiality, integrity, and availability impacts, such as unauthorized control over the device.

Mitigation guidance is available in the CISA ICS Advisory ICSA-25-044-18 at https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-18, with additional vendor contact information at https://www.dingtian-tech.com/en_us/aboutus.html?tab=contact_us. Security practitioners should consult these resources for patching or workaround details specific to the Dingtian DT-R0 Series.

Details

CWE(s)
CWE-288CWE-306

Affected Products

dingtian-tech
dt-r002 firmware
3.1.3044a
dingtian-tech
dt-r008 firmware
3.1.1759a
dingtian-tech
dt-r016 firmware
3.1.2776a
dingtian-tech
dt-r032 firmware
3.1.3826a

References