The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoints of the web interface are vulnerable to arbitrary command injection and use insecure hardcoded passwords. Remote authenticated attackers can gain arbitrary code execution with elevated privileges.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 02 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Jun 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoints of the web interface are vulnerable to arbitrary command injection and use insecure hardcoded passwords. Remote authenticated attackers can gain arbitrary code execution with elevated privileges. | |
| Title | Arbitrary Command Injection in Netcom NTC-6200 & NWL-222 | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ONEKEY
Published: 2025-06-02T07:00:52.366Z
Updated: 2025-06-02T13:33:15.587Z
Reserved: 2025-04-27T08:51:17.231Z
Link: CVE-2025-4010
Updated: 2025-06-02T13:33:06.535Z
Status : Awaiting Analysis
Published: 2025-06-02T07:15:21.833
Modified: 2025-06-02T17:32:17.397
Link: CVE-2025-4010
No data.