VYPR

NR500-EA

by Shenzhen Tuoshi

CVEs (3)

  • CVE-2025-43982CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.00

    Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that cannot be disabled in the GUI.

  • CVE-2024-48440HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.00

    Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.

  • CVE-2025-43989MedAug 13, 2025
    risk 0.42cvss 6.5epss 0.01

    The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandles the set_timesetting action with the ntpserver0 parameter, which is used in a system command. By setting a username=admin cookie (bypassing normal session…