Impact
The vulnerability exists in Beetel 450TC3 firmware 01.00.00_01 and allows an attacker to manipulate the password‑recovery process. This weakness can be leveraged to reset or gain the router’s administrative password, effectively giving the attacker privileged control over the device. The weakness is identified as CWE‑640, reflecting improper authorization assumptions during recovery operations.
Affected Systems
The flaw affects the Beetel 450TC3 product line running firmware version 01.00.00_01. No other versions or related components are listed as affected in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk. The EPSS score is currently not available, but the vulnerability is publicly disclosed and can be executed remotely via the password‑recovery interface. It is not listed in the CISA KEV catalog, suggesting limited exploitation pressure at present, though the remote attack vector is still significant. Attackers who can trigger the recovery mechanism may elevate their access privileges or gain full administrative control.
OpenCVE Enrichment