CVE-2025-1283

The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dingtian-tech:dt-r002_firmware:3.1.3044a:*:*:*:*:*:*:*
cpe:2.3:h:dingtian-tech:dt-r002:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dingtian-tech:dt-r008_firmware:3.1.1759a:*:*:*:*:*:*:*
cpe:2.3:h:dingtian-tech:dt-r008:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dingtian-tech:dt-r016_firmware:3.1.2776a:*:*:*:*:*:*:*
cpe:2.3:h:dingtian-tech:dt-r016:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dingtian-tech:dt-r032_firmware:3.1.3826a:*:*:*:*:*:*:*
cpe:2.3:h:dingtian-tech:dt-r032:-:*:*:*:*:*:*:*

History

10 Apr 2025, 18:55

Type Values Removed Values Added
Summary
  • (es) Dingtian DT-R0 Series es vulnerable a un exploit que permite a los atacantes eludir los requisitos de inicio de sesión navegando directamente a la página principal.
CPE cpe:2.3:h:dingtian-tech:dt-r002:-:*:*:*:*:*:*:*
cpe:2.3:h:dingtian-tech:dt-r008:-:*:*:*:*:*:*:*
cpe:2.3:o:dingtian-tech:dt-r002_firmware:3.1.3044a:*:*:*:*:*:*:*
cpe:2.3:o:dingtian-tech:dt-r032_firmware:3.1.3826a:*:*:*:*:*:*:*
cpe:2.3:h:dingtian-tech:dt-r032:-:*:*:*:*:*:*:*
cpe:2.3:o:dingtian-tech:dt-r016_firmware:3.1.2776a:*:*:*:*:*:*:*
cpe:2.3:o:dingtian-tech:dt-r008_firmware:3.1.1759a:*:*:*:*:*:*:*
cpe:2.3:h:dingtian-tech:dt-r016:-:*:*:*:*:*:*:*
First Time Dingtian-tech dt-r008 Firmware
Dingtian-tech dt-r002 Firmware
Dingtian-tech dt-r016 Firmware
Dingtian-tech
Dingtian-tech dt-r008
Dingtian-tech dt-r032
Dingtian-tech dt-r016
Dingtian-tech dt-r002
Dingtian-tech dt-r032 Firmware
CWE CWE-306
References () https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-18 - () https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-18 - Third Party Advisory, US Government Resource
References () https://www.dingtian-tech.com/en_us/aboutus.html?tab=contact_us - () https://www.dingtian-tech.com/en_us/aboutus.html?tab=contact_us - Product

13 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-13 22:15

Updated : 2025-04-10 18:55


NVD link : CVE-2025-1283

Mitre link : CVE-2025-1283

CVE.ORG link : CVE-2025-1283


JSON object : View

Products Affected

dingtian-tech

  • dt-r032
  • dt-r008
  • dt-r008_firmware
  • dt-r032_firmware
  • dt-r002_firmware
  • dt-r002
  • dt-r016_firmware
  • dt-r016
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel

CWE-306

Missing Authentication for Critical Function