CVE-2026-10045 Details
Description
Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. These vulnerabilities allow attackers to read and write to memory, modify firmware stored in flash, inspect active connections, and view currently connected devices.
A vulnerability exists in the Shenzhen Kangda DR300 router, specifically in version 2.1.2.121. The router comes with hardcoded login credentials and has Telnet enabled by default on both WAN and LAN interfaces. These issues allow attackers to access a shell that can read and write memory, modify firmware in flash storage, inspect active connections, and view connected devices.
The recommended action is to discontinue use of the router, as there is no available method to disable the Telnet service. The combination of hardcoded credentials, plaintext storage of user-configured values, and undocumented remote access via Telnet creates significant security risks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 9, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://rubenabreu.xyz/post/temu-routers-and-their-implications | CISA-ADP | ExploitRemedyTechnical Analysis |
| https://rubenabreu.xyz/post/temu-routers-and-their-implications | [email protected] | ExploitRemedyTechnical Analysis |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Shenzhen Kangda Xin Intelligent Network Technology DR300 | 2.1.2.121 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | New CVE Received | [email protected] |
Volerion