CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-2919: Netis WF-2404 UART hardware allows activation of test or debug logic at runtime

7.0 CVSS

Description

A vulnerability was found in Netis WF-2404 1.1.124EN. It has been declared as critical. This vulnerability affects unknown code of the component UART. The manipulation leads to hardware allows activation of test or debug logic at runtime. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. In Netis WF-2404 1.1.124EN wurde eine Schwachstelle ausgemacht. Sie wurde als kritisch eingestuft. Hierbei betrifft es unbekannten Programmcode der Komponente UART. Durch Beeinflussen mit unbekannten Daten kann eine hardware allows activation of test or debug logic at runtime-Schwachstelle ausgenutzt werden. Ein Angriff setzt physischen Zugriff auf dem Zielobjekt voraus. Der Exploit steht zur öffentlichen Verfügung.

Classification

CVE ID: CVE-2025-2919

CVSS Base Severity: HIGH

CVSS Base Score: 7.0

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem Types

Hardware Allows Activation of Test or Debug Logic at Runtime Active Debug Code

Affected Products

Vendor: Netis

Product: WF-2404

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 3.16% (scored less or equal to compared to others)

EPSS Date: 2025-04-25 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: poc

SSVC Technical Impact: total

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2025-2919
https://vuldb.com/?id.301894
https://vuldb.com/?ctiid.301894
https://vuldb.com/?submit.521036
https://scoozi.substack.com/p/hacking-a-netis-wf-2404-router-with

Timeline