The embedded web interface of the device does not support HTTPS/TLS for
authentication and uses HTTP Basic Authentication. Traffic is encoded
but not encrypted, exposing user credentials to passive interception by
attackers on the same network.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network. | |
| Title | Jinan USR IOT Technology Limited (PUSR) USR-W610 Cleartext Transmission of Sensitive Information | |
| Weaknesses | CWE-319 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-02-20T16:00:42.396Z
Reserved: 2026-02-10T15:52:10.245Z
Link: CVE-2026-24455
No data.
Status : Received
Published: 2026-02-20T17:25:51.143
Modified: 2026-02-20T17:25:51.143
Link: CVE-2026-24455
No data.
OpenCVE Enrichment
No data.