The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an unauthenticated remote attacker could use to execute commands with root privileges.
This vulnerability has been fixed in firmware version: 1.00.67 for CG3000TC and 1.00.27 for CG3000T.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://cert.pl/posts/2026/01/CVE-2025-7072/ |
Configurations
No configuration.
History
09 Jan 2026, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-09 12:15
Updated : 2026-01-13 14:03
NVD link : CVE-2025-7072
Mitre link : CVE-2025-7072
CVE.ORG link : CVE-2025-7072
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials
