CVE-2025-2920

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 28, 2025
Updated: Apr 1, 2025
CWE ID 77

Summary

CVE-2025-2420 exposes a vulnerability in Netis WF-2404 1.1.124EN, which has been classified as problematic. The vulnerability lies in the processing of the /etc/passwd file, resulting in the use of a weak hash. This issue could potentially allow an attacker to launch a physical attack, although the complexity and difficulty of the exploitation are high. The exploit for this vulnerability has been made public, increasing the risk for potential exploitation. Despite early contact, the vendor has not responded to disclosures regarding this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share