Moneycontrol PRO
HomeTechnologyGovernment issues serious warning for broadband users using these Wi-Fi routers: Details and fix you need to know

Government issues serious warning for broadband users using these Wi-Fi routers: Details and fix you need to know

CERT-In warns of serious flaws in Digisol DG-GR6821AC Wi-Fi routers that could lead to hacking. Users must update firmware now to avoid data leaks and unauthorised access.

July 18, 2025 / 20:44 IST
Router

The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity security alert for users of a popular home Wi-Fi router model from Digisol. The advisory, published on July 16, 2025, outlines multiple vulnerabilities that could be exploited by attackers to hijack sessions, steal credentials, or gain unauthorised access to a user’s home or office network. These flaws could leave sensitive data exposed and compromise the overall security of connected devices.

What’s the warning

According to CERT-In, the Digisol DG-GR6821AC Wi-Fi router — specifically those running firmware version V3.2.XX — contains five critical vulnerabilities. These issues include hard-coded credentials, unencrypted storage and transmission of sensitive data, and insecure session cookie handling. The router in question is a dual-mode Optical Network Unit (ONU), commonly used in households and small offices with broadband connections.

The warning states that these vulnerabilities can lead to session hijacking, Man-in-the-Middle (MITM) attacks, and unauthorised network access. Attackers with physical or remote access may be able to extract credentials, monitor traffic, or even take full control of the device.

Check if you are affected

You may be impacted if you are using the Digisol DG-GR6821AC router and have not updated your firmware beyond V3.2.XX. The affected users include home broadband subscribers and administrators managing small office networks.

Here are the identified CVEs:

• CVE-2025-53754: Hard-coded root credentials

• CVE-2025-53755: Storage of unencrypted credentials

• CVE-2025-53756: Cleartext transmission of credentials

• CVE-2025-53757: Missing Secure and HttpOnly cookie flags

• CVE-2025-53758: Use of default admin credentials

Successful exploitation of any of these vulnerabilities could give attackers access to the network, sensitive data, or admin controls.

Fix, you should know

CERT-In recommends that all users immediately update their router firmware to the latest secure version:

HG323DACv5_all_V3.2.02-250509_Digisolver

The update is available for download on Digisol’s official website: https://www.digisol.com/firmware/

Until patched, users should:

• Change default passwords

• Disable remote management features

• Monitor for suspicious activity

• Avoid using unsecured HTTP sessions

 

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Jul 18, 2025 08:35 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347