CVE-2025-62773 Details
Description
Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.
A vulnerability in Mercku M6a routers running firmware through 2.1.0 allows unauthorized telnet access. This is achieved by exploiting a Cross-Site Request Forgery (CSRF) vulnerability in the password change feature, enabling attackers to gain administrative access. Once access is obtained, the hidden telnet server can be activated, providing root access to the device.
Users are advised to implement proper CSRF protection, remove or secure hidden endpoints, use cryptographically secure session generation, enforce session expiration, and follow GPL requirements for OpenWrt modifications.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 22, 2025CISA-ADP
Assessed Oct 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.nullvoid.me/posts/mercku-exploits/ | [email protected] | ExploitRemedyTechnical Analysis |
| https://seclists.org/fulldisclosure/2025/Oct/10 | [email protected] | Mailing ListPartial Content |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-912 | Hidden Functionality | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mercku M6a | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 22, 2025 | New CVE Received | [email protected] |
Volerion