Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Dingtian has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of Dingtian DT-R002 are invited to contact Dingtian customer support https://www.dingtian-tech.com/en_us/aboutus.html for additional information.
Vendor Workaround
The researchers recommend the following to help reduce risk: * Restrict access to HTTP (TCP/80), and the Dingtian Protocol on (UDP/60000) and (UDP/60001).
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31135 | All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request. |
Mon, 29 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dingtian-tech dt-r002 Firmware
|
|
| CPEs | cpe:2.3:h:dingtian-tech:dt-r002:-:*:*:*:*:*:*:* cpe:2.3:o:dingtian-tech:dt-r002_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dingtian-tech dt-r002 Firmware
|
|
| Metrics |
cvssV3_1
|
Fri, 26 Sep 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dingtian-tech
Dingtian-tech dt-r002 |
|
| Vendors & Products |
Dingtian-tech
Dingtian-tech dt-r002 |
Thu, 25 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Sep 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request | All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request. |
Thu, 25 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request | |
| Title | Insufficiently Protected Credentials in Dingtian DT-R002 | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-09-25T18:07:06.076Z
Reserved: 2025-09-23T15:29:33.138Z
Link: CVE-2025-10880
Updated: 2025-09-25T18:01:21.757Z
Status : Analyzed
Published: 2025-09-25T17:15:38.090
Modified: 2025-09-29T14:44:22.307
Link: CVE-2025-10880
No data.
OpenCVE Enrichment
Updated: 2025-09-26T11:35:37Z
EUVD