Missing Authentication for Critical Function in NEC Corporation products - CVE-2025-0355
Published: February 19, 2025
Vulnerability identifier: #VU104062
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-0355
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: NEC Corporation
Affected software:
Aterm WG2600HS
Aterm WF1200CR
Aterm WG1200CR
Aterm GB1200PE
Aterm WG2600HP4
Aterm WG2600HM4
Aterm WG2600HS2
Aterm WX3000HP
Aterm WX4200D5
Aterm WG2600HS
Aterm WF1200CR
Aterm WG1200CR
Aterm GB1200PE
Aterm WG2600HP4
Aterm WG2600HM4
Aterm WG2600HS2
Aterm WX3000HP
Aterm WX4200D5
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to missing authentication for critical function in dloader.php. A remote attacker can obtain the Wi-Fi passwords.
How to mitigate CVE-2025-0355
Install updates from vendor's website.