WODESYS WD-R608U Router Plaintext Password Vulnerability

Vulnerability

A vulnerability exists in the WODESYS WD-R608U router, also known as the WDR122B V2.0 and WDR28, where the admin password is stored in plaintext within the configuration file. This password can be accessed by an unauthorized user through direct references to the file. The issue has been confirmed in the WDR28081123OV1.01 version, while other versions may also be vulnerable.

Impact

Exploitation of this vulnerability allows unauthorized users to obtain the admin password in plaintext, potentially leading to unauthorized access to the router's administrative functions.

Added: Dec 18, 2025, 5:25 PM
Updated: Dec 18, 2025, 5:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.