CVE-2025-2921: Netis WF-2404 passwd default password
A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the file /etc/passwd. The manipulation with the input Realtek leads to use of default password. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2921?
CVE-2025-2921 is classified as a critical vulnerability.
How do I fix CVE-2025-2921?
To fix CVE-2025-2921, change the default password for the device and ensure secure configurations.
What causes the vulnerability CVE-2025-2921?
CVE-2025-2921 is caused by the manipulation of input that leads to the use of a default password in the device's software.
Which devices are affected by CVE-2025-2921?
CVE-2025-2921 affects the Netis WF-2404 model running version 1.1.124EN.
What type of attack can be executed due to CVE-2025-2921?
Due to CVE-2025-2921, an attacker can launch unauthorized access attacks on the physical device.