CVE-2025-46275: Planet Technology Network Products Missing Authentication for Critical Function
WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46275?
CVE-2025-46275 is considered a critical vulnerability due to the lack of authentication that allows unauthorized account creation.
How do I fix CVE-2025-46275?
To fix CVE-2025-46275, update the affected devices to the latest firmware versions provided by Planet Technology.
What products are affected by CVE-2025-46275?
CVE-2025-46275 affects Planet Technology's UNI-NMS-Lite, NMS-500, NMS-1000V, WGS-804HPT-V2, and WGS-4215-8T2S.
What types of attacks can exploit CVE-2025-46275?
CVE-2025-46275 can be exploited by attackers to create unauthorized administrator accounts, leading to potential system compromise.
Is there a workaround for CVE-2025-46275?
Currently, the best approach to mitigate CVE-2025-46275 is to apply the latest firmware updates as no official workaround is provided.