#VU108742 Use of hard-coded credentials in ONS NC600 - CVE-2025-4041
Published: May 7, 2025
Vulnerability identifier: #VU108742
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-4041
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
ONS NC600
ONS NC600
Software vendor:
Optigo Networks
Optigo Networks
Description
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded credentials in application code. A remote unauthenticated attacker can connect with the device's ssh server and utilize the system's componentsm leading to arbitrary OS command execution.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.