Junglewise Threat Intelligence

CVE-2026-7786: Jinan USR IOT USR-W610 hard-coded credentials in firmware

CVE-2026-7786 · Severity: critical · CVSS 9.8 · Published 2026-05-29

Executive brief

The USR-W610 is a hardware converter used to connect industrial serial equipment to Wi-Fi or Ethernet networks. A security flaw exists where administrative passwords are stored in plain text within the device's firmware. An attacker who obtains these credentials can gain full administrative control over the device, potentially disrupting industrial operations or intercepting data transmitted between connected machinery.

Technical details

The USR-W610 RS232/485 to Wi-Fi/Ethernet Converter firmware (version 7.03T.07) contains hard-coded administrative credentials (CWE-798) stored in plaintext. These credentials can be discovered through offline firmware analysis. Once identified, an attacker can use these credentials to authenticate to device services over the network without any prior authorization or user interaction. Successful exploitation grants the attacker full administrative access, enabling them to modify configurations, intercept traffic, or disable the device. As of the advisory date, the vendor has not responded to coordination efforts, and no official patch is available.

Affected products

  • Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter 7.03T.07

Timeline

  • 2026-05-28: advisory: Initial publication of ICSA-26-148-02 by CISA
  • 2026-05-29: disclosed: CVE-2026-7786 published to NVD

References