We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-52376



Description

An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassing security controls. The Telnet server is then accessible with hard-coded credentials, allowing attackers to gain administrative shell access and execute arbitrary commands on the device.

Reserved 2025-06-16 | Published 2025-07-15 | Updated 2025-07-15 | Assigner mitre

References

github.com/Vagebondcur/nexxt-solutions-NCM-X1800-exploits

github.com/...0-exploits/blob/main/CVE-2025-52376/writeup.md

cve.org (CVE-2025-52376)

nvd.nist.gov (CVE-2025-52376)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-52376

Support options

Helpdesk Chat, Email, Knowledgebase