Description
DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email notification credentials and administrative passwords. An attacker with physical access to the device can extract these credentials from an SPI flash dump, leading to device compromise, infiltration of the connected network and unauthorised access to dependent third-party services.
Published: 2026-09-16
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure leading to device compromise and network infiltration
Action: Patch
AI Analysis

Impact

DD‑WRT firmware on TP‑Link TL‑WR740N routers of hardware variants v1 through v4 stores authentication credentials in cleartext inside non‑volatile SPI flash memory. The exposed data includes SSH private keys, dynamic DNS passwords, email notification credentials, and administrative passwords. An attacker who can access the device’s flash memory can recover all of these credentials, effectively compromising the router, gaining administrative authority, and potentially isolating the connected network and any downstream services that rely on those stored keys.

Affected Systems

The affected systems are TP‑Link TL‑WR740N routers of hardware variants v1 through v4 running any DD‑WRT firmware build that includes this cleartext storage bug. Administrators of home or small‑business networks should verify whether their routers are running DD‑WRT and whether the firmware contains this flaw.

Risk and Exploitability

The EPSS score is less than 1 % and the CVE is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at present. The attack vector requires physical access to the device so that the attacker can perform an SPI flash dump. If the credentials are extracted, the attacker gains full control of the router, can infiltrate the connected network, and may abuse third‑party services authenticated with those credentials. The CVSS score of 7.6 highlights a high severity that reflects significant potential impact once the device is compromised.

Generated by OpenCVE AI on September 22, 2026 at 20:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a DD‑WRT firmware release that encrypts stored credentials or removes cleartext credential storage
  • Physically secure the router to prevent unauthorized physical access, such as placing it in a locked cabinet or using tamper‑evident seals
  • After upgrading firmware, change all default and stored credentials, disable unused services, and consider limiting external access to the router with a VPN or firewall rules

Generated by OpenCVE AI on September 22, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Cleartext Storage of Sensitive Credentials in DD-WRT Firmware for TP‑Link TL‑WR740N
Weaknesses CWE-200
CWE-270

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-312
CWE-316
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Cleartext Storage of Sensitive Credentials in DD-WRT Firmware for TP‑Link TL‑WR740N
Weaknesses CWE-200
CWE-270

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email notification credentials and administrative passwords. An attacker with physical access to the device can extract these credentials from an SPI flash dump, leading to device compromise, infiltration of the connected network and unauthorised access to dependent third-party services.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T16:05:48.740Z

Reserved: 2025-08-17T00:00:00.000Z

Link: CVE-2025-56565

cve-icon Vulnrichment

Updated: 2026-09-22T16:04:20.217Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:06.657

Modified: 2026-09-22T19:56:19.073

Link: CVE-2025-56565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:30:08Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information

  • CWE-316

    Cleartext Storage of Sensitive Information in Memory