Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Western Telematic Inc reports this issue was discovered and patched in 2020. Western Telematic Inc recommends users follow best practices and update to the latest version. * For DSM/CPM units: Update to 8.06 https://ftp.wti.com/pub/TechSupport/Firmware_ARM/ * For NPS units: Update 4.02 https://ftp.wti.com/pub/TechSupport/Firmware_ARM/ * Ensure the default passwords are changed prior to deployment
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1798 | Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged access to files on the device's filesystem. |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Feb 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged access to files on the device's filesystem. | |
| Title | Western Telematic Inc NPS Series, DSM Series, CPM Series External Control of File Name or Path | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-02-12T20:51:28.515Z
Reserved: 2025-01-21T20:40:41.730Z
Link: CVE-2025-0630
Updated: 2025-02-12T20:42:41.063Z
Status : Deferred
Published: 2025-02-04T20:15:49.940
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-0630
No data.
OpenCVE Enrichment
No data.
EUVD