go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

WormHole Tech GPM - Unverified Password Change

TVN ID TVN-202505010
CVE ID CVE-2025-4558
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products GPM version before 202502
Description The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
Solution Update to version 202502 or later
Credit Security member
Public Date 2025-05-12
Top