← All CVEs

CVE-2025-4558

critical · 9.3

The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.

9.3
CVSS
0.5%
EPSS (exploit prob.)
42nd
EPSS percentile
2025-05-12
Published

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-620

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-4558