We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-5379

NuCom NC-WR744G Console Application hard-coded credentials



Description

EN DE

A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation of the argument CMCCAdmin/useradmin/CUAdmin leads to hard-coded credentials. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

In NuCom NC-WR744G 8.5.5 Build 20200530.307 wurde eine Schwachstelle entdeckt. Sie wurde als kritisch eingestuft. Betroffen ist eine unbekannte Verarbeitung der Komponente Console Application. Durch Beeinflussen des Arguments CMCCAdmin/useradmin/CUAdmin mit unbekannten Daten kann eine hard-coded credentials-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren.

Reserved 2025-05-30 | Published 2025-05-31 | Updated 2025-06-02 | Assigner VulDB


MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
MEDIUM: 4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.0AV:N/AC:L/Au:S/C:P/I:N/A:N

Problem types

Hard-coded Credentials

Use of Hard-coded Password

Product status

8.5.5 Build 20200530.307
affected

Timeline

2025-05-30:Advisory disclosed
2025-05-30:VulDB entry created
2025-05-30:VulDB entry last update

Credits

matuii (VulDB User) reporter

References

vuldb.com/?id.310672 (VDB-310672 | NuCom NC-WR744G Console Application hard-coded credentials) vdb-entry technical-description

vuldb.com/?ctiid.310672 (VDB-310672 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.582868 (Submit #582868 | NuCom NC-WR744G 8.5.5 (Build:20200530.307-TEMP) Cleartext Storage of Sensitive Information) third-party-advisory

cve.org (CVE-2025-5379)

nvd.nist.gov (CVE-2025-5379)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-5379

Support options

Helpdesk Chat, Email, Knowledgebase