CVE-2025-7882 Details
Description
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
An excessive authentication vulnerability has been identified in the Mercusys MW301R router, specifically in version 1.0.2 Build 190726 Rel.59423n. This vulnerability arises from the router's login component, which fails to adequately limit the number of authentication attempts. As a result, the device is susceptible to brute-force attacks. The issue can only be exploited from within the local network, and while the vulnerability has been publicly disclosed and an exploit is available, the exploitation is considered difficult.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 20, 2025CISA-ADP
Assessed Jul 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/RaulPazemecxas/PoCVulDb/blob/main/README21.md | [email protected] | Broken LinkExploit |
| https://vuldb.com/?ctiid.316997 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?id.316997 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.611431 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
| CWE-799 | Improper Control of Interaction Frequency | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mercusys MW301R | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jul 20, 2025 | New CVE Received | [email protected] |
Volerion