Skip to main content
Mallory
Critical

Hardcoded Administrative Credentials in PUSR USR-W610 Firmware

IdentifiersCVE-2026-7786CWE-798· Use of Hard-coded Credentials

CVE-2026-7786 affects the Jinan USR IOT Technology (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter. The device firmware contains plaintext administrative credentials embedded directly in the firmware image/system image. These credentials can be recovered through firmware analysis and then used to authenticate to exposed device services. The vulnerability is therefore a hardcoded credential issue in which sensitive administrative authentication material is statically present in shipped firmware, enabling unauthorized access once extracted.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker to recover valid administrative credentials and obtain unauthorized administrative access to the affected converter. With administrative control of the device, an attacker may hijack the connectivity device, intercept or modify data traversing between connected machines, disrupt trusted serial-to-network communications, and use the device as a foothold for lateral movement into adjacent local or operational technology networks. The provided context characterizes the issue as critical and assigns a CVSS score of 9.8.

Mitigation

If you can’t patch tonight, do this now.

Immediate defensive measures identified in the provided content are to isolate affected assets, enforce strict access control lists around device access, and disable management interfaces exposed to the public internet. More broadly, management access should be restricted to trusted administrative networks only until a vendor fix or credential rotation mechanism is available. The provided content does not include a confirmed vendor patch or firmware update.

Remediation

Patch, then assume compromise.

Remove embedded static administrative credentials from the firmware and redesign authentication so that each device requires unique credentials provisioned securely at manufacture or first boot. Rotate or invalidate any affected credentials, release updated firmware that eliminates plaintext hardcoded secrets, and require administrators to change default or recovered passwords after upgrade. If the same credentials are shared across devices, treat them as compromised fleet-wide.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity7

Community discussion across Reddit, Mastodon, and other social sources.