Back

CRITICAL

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter Use of Hard-coded Credentials

Published May 29, 2026

Description

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and used to authenticate to device services.

Affected products

Remediation

Vendor solution

Jinan USR IOT Technology Limited (PUSR) did not respond to CISA's attempts at coordination. Users of PUSR USR-W610 devices are encouraged to contact PUSR and keep their systems up to date.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published May 29, 2026
Updated May 29, 2026
Reserved May 4, 2026

CISA Vulnrichment

Updated May 29, 2026

NVD

Status Deferred
Modified Jul 21, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published May 29, 2026
Updated May 29, 2026

GitHub

No data