First published: Fri Mar 28 2025(Updated: )
A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the file /etc/passwd. The manipulation with the input Realtek leads to use of default password. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netis Wf-2404 Firmware | ||
All of | ||
Netis Wf-2404 Firmware | =1.1.124en | |
Netis WF-2404 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2921 is classified as a critical vulnerability.
To fix CVE-2025-2921, change the default password for the device and ensure secure configurations.
CVE-2025-2921 is caused by the manipulation of input that leads to the use of a default password in the device's software.
CVE-2025-2921 affects the Netis WF-2404 model running version 1.1.124EN.
Due to CVE-2025-2921, an attacker can launch unauthorized access attacks on the physical device.