CVE-2026-24455: Jinan Usr IoT Technology Limited Pusr Usr-w610

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.

Affected products

Published 2026-02-20. Last modified 2026-06-17.