Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 202502
affected
Description
The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
Problem types
CWE-620 Unverified Password Change
Product status
Any version before 202502
References
www.twcert.org.tw/tw/cp-132-10114-10b4b-1.html
www.twcert.org.tw/en/cp-139-10115-f5f14-2.html