Junglewise Threat Intelligence

CVE-2026-82487: Beetel 450TC3 privilege escalation in password change function

CVE-2026-82487 · Severity: medium · CVSS 6.3 · Published 2026-08-30

Executive brief

The Beetel 450TC3 is a router used in residential and small office networks. A vulnerability in its web management interface allows low-privileged users to change the administrator password without authorization, granting them full control over the device, including network settings and user account management.

Technical details

An authenticated privilege escalation vulnerability exists in the Beetel 450TC3 router firmware V01.00.00_01 due to improper authorization checking in the password change functionality (CWE-269). A low-privileged authenticated user can intercept their password change HTTP request and modify the target username parameter to the administrator account, bypassing the authorization check. The application does not validate the current administrator password before processing the change request, allowing an attacker to reset the admin password and gain full administrative access. The vulnerability requires authentication to the router's web interface but no admin credentials, and can be exploited via HTTP interception.

Affected products

  • Beetel 450TC3 01.00.00_01

Timeline

  • 2026-08-30: disclosed: Vulnerability publicly disclosed on GitHub
  • 2026-08-30: other: Vendor unresponsive to early disclosure

References

Related threats