#VU108742 Use of hard-coded credentials in ONS NC600 - CVE-2025-4041

 

#VU108742 Use of hard-coded credentials in ONS NC600 - CVE-2025-4041

Published: May 7, 2025


Vulnerability identifier: #VU108742
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-4041
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
ONS NC600
Software vendor:
Optigo Networks

Description

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to presence of hard-coded credentials in application code. A remote unauthenticated attacker can connect with the device's ssh server and utilize the system's componentsm leading to arbitrary OS command execution.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links