According to a CISA advisory (ICSA-26-148-02), the Jinan USR IOT Technology Limited USR-W610 RS232/485 to Wi-Fi/Ethernet Converter contains a vulnerability that, if successfully exploited, could result in an attacker gaining administrator access to the device. CISA has issued an official advisory with technical details available through their ICS-CERT channel.
The USR-W610 is an industrial protocol converter—a bridge between legacy RS232/485 serial devices and modern Ethernet/Wi-Fi networks. These devices are common in manufacturing, utilities, HVAC systems, and other OT (operational technology) environments where older equipment needs to communicate with networked infrastructure.
Administrator-level access to such a converter is a serious concern because it enables an attacker to:
- Intercept or manipulate data flowing between industrial devices and control systems
- Modify device configurations to persist access
- Potentially pivot to adjacent systems on the same network
- Disrupt or alter sensor readings and equipment commands
The advisory is currently in early reporting (first flagged May 28, 2026), and CISA's CSAF technical documentation is available for detailed analysis. Organizations using USR-W610 converters should verify their deployed versions against the affected list and prioritize patching or isolation of these devices in critical OT networks.
What to watch: Monitor CISA advisories for proof-of-concept code release, patch availability from Jinan USR IOT, and any reports of active exploitation in the wild. Industrial systems are often slower to patch than IT infrastructure, which may extend the window of vulnerability exposure.
