CVE-2025-8731
Last modified
CVE-2025-8731 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains: "For product TI-PG102i and TI-G160i, by default, the product's remote management options are all disabled. The root account is for troubleshooting purpose and the password is encrypted. However, we will remove the root account from the next firmware release. For product TPL-430AP, the initial setup process requires user to set the password for the management GUI. Once that was done, the default password will be invalid."
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-8731?
How severe is CVE-2025-8731?
How do I fix CVE-2025-8731?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8722The Content Views plugin for WordPress is vulnerable to Stor…6.4
- CVE-2025-8723The Cloudflare Image Resizing plugin for WordPress is vulner…9.8
- CVE-2025-8726The WP Photo Album Plus plugin for WordPress is vulnerable t…5.4
- CVE-2025-8727There is a vulnerability in the Supermicro BMC web function …7.2
- CVE-2025-8729A vulnerability has been found in MigoXLab LMeterX 1.2.0 and…9.1
- CVE-2025-8730A vulnerability was found in Belkin F9K1009 and F9K1010 2.00…9.8
- CVE-2025-8732A vulnerability was found in libxml2 up to 2.14.5. It has be…3.3
- CVE-2025-8733Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2025-8734Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2025-8735A vulnerability classified as problematic was found in GNU c…3.3
- CVE-2025-8736A vulnerability, which was classified as critical, has been …5.3
- CVE-2025-8737A vulnerability, which was classified as problematic, was fo…3.5
Are you affected by CVE-2025-8731?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
