CVE-2025-2921
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 28, 2025
Updated: Apr 17, 2025
CWE ID 121
Summary
CVE-2025-2421: A critical vulnerability has been identified in the Netis WF-2404 1.1.124EN device. This issue lies within an unnamed function of the /etc/passwd file, which can be exploited through manipulation of the Realtek input. The attack allows the use of default passwords and potentially grants attackers access to the physical device. The complexity of the attack is reported to be high, and exploitability is considered difficult, but an exploit has been made public. Despite early contact, the vendor has not responded to disclosure efforts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.