KAON CG3000T and CG3000TC routers contain hardcoded credentials allowing unauthenticated…
KAON CG3000T and CG3000TC routers contain hardcoded credentials allowing unauthenticated remote root access; patches available.
CERT Polska coordinated the disclosure of a critical vulnerability affecting KAON CG3000T and CG3000TC routers. The vulnerability, tracked as CVE-2025-7072, involves hardcoded credentials stored in cleartext within the firmware that are shared across all routers of these models. An unauthenticated remote attacker can exploit these credentials to execute arbitrary commands with root privileges on affected devices.
The vulnerability represents a complete compromise scenario for affected routers, as it requires no authentication and grants the highest level of system access. KAON has released firmware updates to address the issue: version 1.00.67 for CG3000TC and version 1.00.27 for CG3000T. Organizations and individuals using these router models should prioritize updating to the patched firmware versions immediately.
The vulnerability was responsibly disclosed by security researcher Piotr Ługowski through CERT Polska's coordinated vulnerability disclosure process. The presence of shared hardcoded credentials across an entire product line significantly amplifies the risk, as knowledge of these credentials can be used against any unpatched device of these models worldwide.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/01/CVE-2025-7072
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free