CVE-2025-23384

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published Mar 11, 2025
CWE ID 187

Summary

CVE-2025-23384 is a vulnerability affecting multiple RUGGEDCOM and SCALANCE router models, including RM1224 LTE, M804PB, M812-1 ADSL-Router family, M816-1 ADSL-Router family, M826-2 SHDSL-Router, M874-2, M874-3, M876-3 (A1, B1, EU, NAM, RoW), M876-4 (EU, NAM), MUB852-1 (A1, B1), MUM853-1 (A1, B1, EU), MUM856-1 (A1, B1, CN, EU, RoW), and S615 EEC LAN-Router, S615 LAN-Router, and the SC-600 family. The affected devices have a flaw in their OpenVPN authentication process, allowing partial invalid usernames to be accepted by the server. An attacker could exploit this vulnerability to gain unauthorized access to the affected network. Users are advised to update their devices to version V8.2.1 or later to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share