PatchSiren cyber security CVE debrief
CVE-2025-1283 Dingtian CVE debrief
CVE-2025-1283 affects the Dingtian DT-R0 series, including DT-R002, DT-R008, DT-R016, and DT-R032 in the versions named by CISA. The advisory says an attacker can bypass login requirements by directly navigating to the main page. CISA rates the issue CVSS 3.1 9.8 (critical) and states that no mitigation is available at this time.
- Vendor
- Dingtian
- Product
- DT-R002
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-13
- Original CVE updated
- 2025-02-13
- Advisory published
- 2025-02-13
- Advisory updated
- 2025-02-13
Who should care
OT/ICS asset owners, plant operators, and security teams that manage Dingtian DT-R0 devices, especially where device management interfaces are reachable from broader internal networks or remote access paths.
Technical summary
CISA's CSAF advisory describes an authentication-bypass condition in the Dingtian DT-R0 series. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network-exploitable impact with no privileges and no user interaction required. Affected products listed by CISA are Dingtian DT-R002 V3.1.3044A, DT-R008 V3.1.1759A, DT-R016 V3.1.2776A, and DT-R032 V3.1.3826A.
Defensive priority
Immediate (critical)
Recommended defensive actions
- Inventory all Dingtian DT-R0 series devices and verify whether any are running the affected versions listed in the advisory.
- Restrict access to device management interfaces and remove any direct exposure from untrusted or broadly accessible networks.
- Use compensating controls such as OT network segmentation, VPN or jump-host access, and allowlisting for administrative paths.
- Review device and network logs for unexpected administrative access or other suspicious activity affecting these devices.
- Follow the CISA advisory and contact Dingtian support for product-specific guidance; the advisory states no mitigation is available at this time.
Evidence notes
This debrief is based on CISA's CSAF advisory ICSA-25-044-18 and the supplied advisory metadata, all published on 2025-02-13. The source explicitly names the affected Dingtian DT-R0 series products and versions and states that Dingtian had not responded to mitigation requests, so no mitigation was available at publication.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-1283 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-1283
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-1283 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-1283
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-18.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-18
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.