Dingtian DT-R002 Insufficiently Protected Credentials Vulnerability

Vulnerability

A vulnerability exists in all versions of the Dingtian DT-R002 relay board, allowing attackers to extract the proprietary 'Dingtian Binary' protocol password. This insufficiently protected credentials vulnerability can be exploited by sending an unauthenticated GET request.

Impact

Exploitation of this vulnerability could lead to unauthorized extraction of the 'Dingtian Binary' protocol password.

Remediation

Dingtian has not responded to requests for mitigation. Users are advised to contact Dingtian customer support for more information. It is also recommended to restrict access to HTTP (TCP/80) and the Dingtian Protocol on UDP/60000 and UDP/60001. CISA suggests minimizing network exposure for control system devices, using firewalls to isolate control system networks from business networks, and employing secure remote access methods like VPNs.

Added: Sep 25, 2025, 5:19 PM
Updated: Sep 25, 2025, 5:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
7.0
remediation
8.3
relevance
0.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.