Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4558


The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.


Published

2025-05-12T04:15:35.160

Last Modified

2025-05-12T17:32:32.760

Status

Awaiting Analysis

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-620

Affected Vendors & Products

-


References