Sceawere

Vulnerability Detail

CVE-2026-82487UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Beetel 450TC3 Weak Password Recovery

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
Beetel
Product
450TC3
Attack Type
Weak Password Recovery
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-30T10:17:16.287Z",
  "pubdate": "2026-08-30T10:17:16.287Z",
  "executiveSummary": "The Beetel 450TC3, version 01.00.00_01, contains a security vulnerability related to its password recovery mechanism. This flaw permits an unauthorized remote attacker to manipulate the recovery process to compromise user account integrity.\nThe vulnerability is categorized as a weak password recovery implementation. Because the device is accessible over the network, this vulnerability allows for remote exploitation, potentially leading to unauthorized access to the device management interface.\nThe vendor was notified regarding this disclosure but failed to provide a response, meaning no official security patch is available to remediate this issue.\nGiven the publicly disclosed nature of this exploit, the risk level is elevated, as the barrier to entry for potential attackers is low. Organizations utilizing this device should consider it a security risk and implement compensating controls to mitigate unauthorized access.",
  "technicalDetails": "The vulnerability resides within the password recovery subsystem of the Beetel 450TC3 firmware (version 01.00.00_01). The root cause is an insecure implementation of the recovery logic, which fails to securely validate user identity or sufficiently protect the password reset token generation process.\nThe exploitation method relies on the ability of an attacker to interact with the device's web-based management interface remotely. By crafting specific network requests aimed at the password recovery endpoint, an attacker can influence the state of the authentication mechanism.\nAttack flow: An attacker initiates a password recovery request to the vulnerable endpoint on the device. Due to the insecure design, the device fails to authenticate the requestor or verify that they are the legitimate owner of the target account. The attacker manipulates the parameters of the request—such as session tokens, hidden form fields, or sequence IDs—to bypass the intended validation checks. Following this manipulation, the system improperly authorizes the password reset, allowing the attacker to establish a new password for an administrative or user account of their choosing.\nThis vulnerability is reachable over the network (remote exposure), and successful exploitation does not require prior authentication or elevated privileges. Because the logic flaws occur in the core authentication handling, the payload behavior effectively resets the target account credentials without triggering standard security alerts.\nThe post-exploitation impact allows an unauthorized individual to gain full control over the device. This provides the attacker with the ability to modify device settings, intercept or reroute traffic, deploy persistent malware within the device firmware, or leverage the device as a pivot point for lateral movement within the network infrastructure."
}
CVE-2026-82487: Beetel 450TC3 Weak Password Recovery (MEDIUM Severity, CVSS: 6.3) - Sceawere