CVE-2025-4558: WormHole Tech GPM - Unverified Password Change

9.8 CVSS

Description

The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.

Classification

CVE ID: CVE-2025-4558

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem Types

CWE-620 Unverified Password Change

Affected Products

Vendor: WormHole Tech

Product: GPM

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.11% (probability of being exploited)

EPSS Percentile: 30.65% (scored less or equal to compared to others)

EPSS Date: 2025-06-07 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-4558
https://www.twcert.org.tw/tw/cp-132-10114-10b4b-1.html
https://www.twcert.org.tw/en/cp-139-10115-f5f14-2.html

Timeline