Junglewise Threat Intelligence

CVE-2025-29268: ALLNET ALL-RUT22GW hardcoded credentials in libicos.so

CVE-2025-29268 · Severity: critical · CVSS 9.8 · Published 2025-12-04

Executive brief

ALLNET industrial cellular routers contain a hardcoded backdoor account within their authentication library. This router is typically used in industrial IoT and machine-to-machine environments to provide network connectivity. An attacker can use these fixed credentials to bypass security and gain full administrative access to the device's web management panel, allowing them to intercept data, modify network settings, or disrupt industrial operations.

Technical details

A hardcoded backdoor account was identified in the libicos.so library used by the ALLNET ALL-RUT22GW industrial router. The vulnerability stems from the ICOS_CheckPrivilege function, which compares user-provided credentials against a fixed password hash stored in the binary's data section. By providing these hardcoded credentials, a remote, unauthenticated attacker can gain 'system' level privileges (the highest access level) via the web management interface. This allows for complete device takeover, including the ability to modify configuration and monitor traffic. The flaw is present in firmware version 3.3.8.

Affected products

  • ALLNET ALL-RUT22GW Compact Industrial 4G LTE Cellular Router 3.3.8

Timeline

  • 2025-12-01: disclosed: Initial discovery and write-up by ByteRay (Vortex)
  • 2025-12-04: advisory: CVE-2025-29268 published by NVD/MITRE

References

Related threats