Executive brief
The Shenzhen Kangda Xin DR300 router contains built-in, unchangeable login credentials and leaves its remote management service (Telnet) open to the internet by default. This allows unauthorized individuals to take complete control of the device, potentially leading to the theft of internet traffic data, modification of the device's software, or use of the router as a foothold to attack other devices on the local network. Business operations could be disrupted by unauthorized configuration changes or permanent damage to the hardware's firmware.
Technical details
The DR300 router (firmware version 2.1.2.121) suffers from the use of hardcoded credentials combined with an insecure default configuration that enables the Telnet service on both WAN and LAN interfaces. An attacker can connect to the device over the network using these static credentials to gain shell access. Once authenticated, the attacker can read/write to system memory, modify the firmware stored in flash memory, monitor active network connections, and view all connected client devices. This effectively grants persistent, root-level control over the appliance.
Affected products
- Shenzhen Kangda Xin Intelligent Network Technology Company DR300 Router 2.1.2.121
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory