CVE-2025-9725 | Cudy LT500E up to 2.3.12 Web Interface shadow hard-coded password (EUVD-2025-26291)
A vulnerability classified as problematic has been found in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/etc/shadow of the component Web Interface. The manipulation leads to use of hard-coded password.
This vulnerability is listed as CVE-2025-9725. The attack must be carried out locally. In addition, an exploit is available.
It is recommended to upgrade the affected component.
The vendor explains: "[T]he firmware does store a default password of 'admin'. This password has been deprecated since LT500E firmware version 2.3.13 and is no longer used. The LT500E does not have an administrator password set by default; a new password (at least 8 characters ) must be manually created upon first login the web management page."