# KAON routers CVE-2025-7072: hardcoded root credentials

Published: 2026-01-09 · Severity: high · Sectors: telecommunications
Canonical: https://vorant.io/reports/e332768e-604b-50f3-b26a-1c8a4c31727b/kaon-routers-cve-2025-7072-hardcoded-root-credentials

> KAON CG3000T and CG3000TC routers contain hardcoded credentials enabling unauthenticated remote root command execution; patches available.

CERT Polska coordinated disclosure of CVE-2025-7072, a critical vulnerability affecting KAON CG3000T and CG3000TC routers. The firmware contains hardcoded credentials stored in cleartext that are shared across all devices of these models. An unauthenticated remote attacker can leverage these credentials to execute arbitrary commands with root privileges on affected routers.

The vulnerability was responsibly reported by Piotr Ługowski. KAON has released patched firmware versions that address this issue: version 1.00.67 for CG3000TC and version 1.00.27 for CG3000T. Organizations and consumers using these router models should immediately upgrade to the fixed firmware versions to eliminate this attack vector.

Hardcoded credential vulnerabilities in network infrastructure devices represent a significant security risk, particularly when credentials are shared across an entire product line. The remote, unauthenticated nature of this exploit path makes it especially attractive for threat actors seeking to compromise edge network devices for initial access or botnet recruitment.

## Mentioned in this report

- Vulnerabilities: CVE-2025-7072

Source reporting: https://cert.pl/en/posts/2026/01/CVE-2025-7072

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e332768e-604b-50f3-b26a-1c8a4c31727b/kaon-routers-cve-2025-7072-hardcoded-root-credentials.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
