A widely deployed industrial converter from Chinese manufacturer PUSR ships with administrator credentials stored in plaintext inside its firmware image.
CISA flagged CVE-2026-7786 in the USR-W610, a device that bridges legacy RS232/485 serial equipment to Wi-Fi and Ethernet, the kind of hardware common on factory floors and industrial sites. Firmware version 7.03T.07 embeds administrative credentials unencrypted in the binary, meaning anyone who downloads and disassembles the image can extract them. Those credentials authenticate directly against live devices over the network. The flaw scores 9.8 out of 10 on the CVSS scale, the highest tier possible, because exploitation requires no authentication, no user interaction, and no special network position.
Industrial control system devices sit at the boundary between digital networks and physical machinery, so administrator access here is a real-world hazard, not just a data-theft problem. PUSR did not respond to CISA's coordination attempts, leaving users with no patch and no timeline for one; network segmentation and VPNs are the only options on the table.
Hard-coded credentials have been a documented vulnerability class since at least the Mirai botnet era, when attackers used factory-default passwords to conscript millions of IoT devices into DDoS campaigns. That manufacturers are still shipping firmware with plaintext credentials a decade later is less a technical failure than an organizational one.
