CVE-2025-6097: UTT 进取 750W Administrator Password setSysAdm formDefineManagement unverified password change
A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function formDefineManagement of the file /goform/setSysAdm of the component Administrator Password Handler. The manipulation of the argument passwd1 leads to unverified password change. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6097?
CVE-2025-6097 is classified as a critical vulnerability.
How do I fix CVE-2025-6097?
To mitigate CVE-2025-6097, update the UTT 进取 750W software to version 5.0 or later.
What components are affected by CVE-2025-6097?
CVE-2025-6097 affects the Administrator Password Handler component in the UTT 进取 750W.
What type of vulnerability is CVE-2025-6097?
CVE-2025-6097 is a manipulation vulnerability that involves unverified password handling.
Where can I find additional information about CVE-2025-6097?
Details regarding CVE-2025-6097 can typically be found in the official documentation or security advisories from UTT.