Description
A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Weak password recovery provides unauthenticated or low‑privilege attackers the ability to reset or retrieve administrative credentials on the router
Action: Patch Immediately
AI Analysis

Impact

The vulnerability exists in Beetel 450TC3 firmware 01.00.00_01 and allows an attacker to manipulate the password‑recovery process. This weakness can be leveraged to reset or gain the router’s administrative password, effectively giving the attacker privileged control over the device. The weakness is identified as CWE‑640, reflecting improper authorization assumptions during recovery operations.

Affected Systems

The flaw affects the Beetel 450TC3 product line running firmware version 01.00.00_01. No other versions or related components are listed as affected in the CNA data.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity risk. The EPSS score is currently not available, but the vulnerability is publicly disclosed and can be executed remotely via the password‑recovery interface. It is not listed in the CISA KEV catalog, suggesting limited exploitation pressure at present, though the remote attack vector is still significant. Attackers who can trigger the recovery mechanism may elevate their access privileges or gain full administrative control.

Generated by OpenCVE AI on August 30, 2026 at 11:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest vendor‑supplied version that addresses the password‑recovery flaw
  • If a patch is unavailable, disable or restrict remote password‑recovery functionality to trusted internal networks only
  • Enforce strong, unique administrative passwords, change default credentials, and monitor logs for suspicious recovery attempts

Generated by OpenCVE AI on August 30, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 30 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Beetel 450TC3 password recovery
First Time appeared Beetel
Beetel 450tc3
Weaknesses CWE-640
CPEs cpe:2.3:a:beetel:450tc3:*:*:*:*:*:*:*:*
Vendors & Products Beetel
Beetel 450tc3
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-01T14:00:27.723Z

Reserved: 2026-08-29T16:29:25.853Z

Link: CVE-2026-82487

cve-icon Vulnrichment

Updated: 2026-09-01T14:00:23.029Z

cve-icon NVD

Status : Deferred

Published: 2026-08-30T10:17:16.287

Modified: 2026-09-01T14:17:45.603

Link: CVE-2026-82487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T11:19:13Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password