NONE · 0

CVE-2025-56565

DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private...

Vulnerability Description

DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email notification credentials and administrative passwords. An attacker with physical access to the device can extract these credentials from an SPI flash dump, leading to device compromise, infiltration of the connected network and unauthorised access to dependent third-party services.

References

FAQ

What is CVE-2025-56565?

CVE-2025-56565 is a documented vulnerability. DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private...

How severe is CVE-2025-56565?

CVSS scoring is not yet available for CVE-2025-56565. Check NVD for updates.

Is there a patch for CVE-2025-56565?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.