The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
CVE ID: CVE-2025-4558
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor: WormHole Tech
Product: GPM
EPSS Score: 0.11% (probability of being exploited)
EPSS Percentile: 30.65% (scored less or equal to compared to others)
EPSS Date: 2025-06-07 (when was this score calculated)