6.4 CVE-2025-2921

 

A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the file /etc/passwd. The manipulation with the input Realtek leads to use of default password. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
https://nvd.nist.gov/vuln/detail/CVE-2025-2921

Categories

CWE-1393 : Use of Default Password
It is common practice for products to be designed to usedefault passwords for authentication. The rationale is tosimplify the manufacturing process or the systemadministrator's task of installation and deployment into anenterprise. However, if admins do not change the defaults,then it makes it easier for attackers to quickly bypassauthentication across multiple organizations. There are manylists of default passwords and default-password scanning toolsthat are easily available from the World Wide Web.

References


 

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry