CVE-2025-0355: High severity nec aterm wg2600hs firmware vulnerability
Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to get a Wi-Fi password via the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0355?
CVE-2025-0355 is considered a critical vulnerability due to its potential exploitation without authentication.
How do I fix CVE-2025-0355?
To fix CVE-2025-0355, upgrade your NEC device firmware to the latest version that addresses the authentication issue.
Which NEC products are affected by CVE-2025-0355?
CVE-2025-0355 affects several NEC products including Aterm WG2600HS, WF1200CRS, WG1200CRS, and others listed in the vulnerability description.
What happens if I don't address CVE-2025-0355?
If CVE-2025-0355 is not addressed, attackers could gain unauthorized access to critical functions of the affected NEC devices.
Is there a workaround for CVE-2025-0355?
Currently, there are no documented workarounds for CVE-2025-0355 other than upgrading to a patched firmware version.