Multiple security advisories have identified critical vulnerabilities in all versions of the Dingtian DT-R002 relay board, which is used in various industrial and critical infrastructure environments. The primary issue, tracked as CVE-2025-10879, involves insufficiently protected credentials, allowing remote attackers to retrieve the current user's username without requiring authentication. This vulnerability is considered highly severe, with a CVSS v4 base score of 8.7, indicating a significant risk if exploited. The vulnerability is remotely exploitable and requires low attack complexity, making it accessible to a wide range of threat actors. According to the CISA advisory, successful exploitation could enable attackers to gain unauthorized access to sensitive information, potentially facilitating further attacks or lateral movement within affected networks. The Dingtian DT-R002 relay board is widely deployed, and all versions are confirmed to be vulnerable, increasing the potential impact across multiple sectors. In addition to CVE-2025-10879, the CISA advisory also highlights a related vulnerability, CVE-2025-10880, which allows attackers to extract the proprietary "Dingtian Binary" protocol password via an unauthenticated GET request. Both vulnerabilities stem from insufficient credential protection mechanisms, underscoring systemic security weaknesses in the product's authentication design. The advisories recommend that organizations using the Dingtian DT-R002 relay board assess their exposure and implement mitigations as soon as possible. No specific affected product versions are listed, but the advisories confirm that all versions are impacted. The vulnerabilities were reported to ICS-CERT, and the advisories were published to alert critical infrastructure operators and other stakeholders. The exposure of credentials without authentication poses a risk of unauthorized access, data leakage, and potential disruption of industrial processes. Organizations are urged to monitor for further updates from Dingtian and relevant security authorities. The high severity scores reflect the ease of exploitation and the potential consequences for affected environments. Security teams should prioritize network segmentation, access controls, and monitoring for anomalous activity related to the Dingtian DT-R002. The advisories do not mention the availability of patches, so compensating controls may be necessary until vendor updates are released. The vulnerabilities highlight the importance of secure credential management in industrial control systems. Failure to address these issues could result in compromise of critical infrastructure assets. The coordinated disclosure and public advisories aim to drive rapid remediation and awareness across the sector.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A second high-severity vulnerability, CVE-2025-10880, was publicly listed for the Dingtian DT-R002 and described as insufficiently protected credentials. This disclosure added another distinct credential-protection issue affecting the same product.
A high-severity vulnerability, CVE-2025-10879, was publicly listed for the Dingtian DT-R002 and described as insufficiently protected credentials. The disclosure identified one of the specific credential-protection flaws affecting the device.
CISA released ICS advisory ICSA-25-268-01 covering security issues affecting the Dingtian DT-R002 device. The advisory marks the public disclosure of the vulnerabilities impacting the product.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.