A critical vulnerability (CVE-2026-7786, CVSS 9.8) affects the Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter. The device firmware version 7.03T.07 contains hard-coded plaintext administrative credentials, allowing unauthenticated remote attackers to extract the credentials and gain full administrator access to the device. The vendor has not responded to coordination attempts, necessitating immediate network isolation of affected devices.
PUSR USR-W610
1 post
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter