CVE-2025-46273
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 798
Summary
CVE-2025-46273 is a vulnerability affecting UNI-NMS-Lite, in which the software utilizes hard-coded credentials. An attacker without authentication can exploit this weakness to seize administrative control over all UNI-NMS-managed devices. This poses a significant risk, as unauthorized access could lead to unintended modifications, unauthorized data access, and potential system compromise. It is strongly recommended to update UNI-NMS-Lite to a version that does not contain these hard-coded credentials to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- UNI-NMS-Lite
Affected Vendors
- Planet Tech