#VU104062 Missing Authentication for Critical Function in NEC Corporation products - CVE-2025-0355
Published: February 19, 2025
Vulnerability identifier: #VU104062
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-0355
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Aterm WG2600HS
Aterm WF1200CR
Aterm WG1200CR
Aterm GB1200PE
Aterm WG2600HP4
Aterm WG2600HM4
Aterm WG2600HS2
Aterm WX3000HP
Aterm WX4200D5
Aterm WG2600HS
Aterm WF1200CR
Aterm WG1200CR
Aterm GB1200PE
Aterm WG2600HP4
Aterm WG2600HM4
Aterm WG2600HS2
Aterm WX3000HP
Aterm WX4200D5
Software vendor:
NEC Corporation
NEC Corporation
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to missing authentication for critical function in dloader.php. A remote attacker can obtain the Wi-Fi passwords.
Remediation
Install updates from vendor's website.