CVE-2025-4558

The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
Configurations

No configuration.

History

12 May 2025, 17:32

Type Values Removed Values Added
Summary
  • (es) El GPM de WormHole Tech tiene una vulnerabilidad de cambio de contraseña no verificado, que permite a atacantes remotos no autenticados cambiar la contraseña de cualquier usuario y usar la contraseña modificada para iniciar sesión en el sistema.

12 May 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-12 04:15

Updated : 2025-05-12 17:32


NVD link : CVE-2025-4558

Mitre link : CVE-2025-4558

CVE.ORG link : CVE-2025-4558


JSON object : View

Products Affected

No product.

CWE
CWE-620

Unverified Password Change