Source: Ministry of education information & communication security contingency platform
| Publication Number | TACERT-ANA-2025051309055757 | Publication Time | 2025/05/13 09:19 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2025/05/13 09:19 |
| Impact Level | Low | ||
| [Subject] [Vulnerability Alert] Wormhole Technology GPM – Unverified Password Change |
|||
| [Content] Forwarded from TWCERTCC-200-202505-00000011 [Wormhole Technology GPM – Unverified Password Change] (CVE-2025-4558, CVSS: 9.8) A Unverified Password Change vulnerability exists in Wormhole Technology’s GPM. Remote unauthenticated attackers can exploit this flaw to modify any user's password and then log into the system using the newly set credentials. Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform] Versions prior to GPM 202502 |
|||
| [Recommended Actions] Please update to version 202502 or later. |
|||
| [Reference] Wormhole Technology GPM – Unverified Password Change: https://www.twcert.org.tw/tw/cp-132-10114-10b4b-1.html |
|||