allow an attacker to create an administrator account without knowing any
existing credentials.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Planet Technology has released patches for the following devices: * WGS-804HPT (v2) https://www.planet.com.tw/en/product/wgs-804hpt-v2 * WGS-4215-8T2 https://www.planet.com.tw/en/product/wgs-4215-8t2s * S https://www.planet.com.tw/en/product/wgs-4215-8t2s UNI-NMS https://www.planet.com.tw/en/product/uni-nms * NMS-500 https://www.planet.com.tw/en/product/nms-500 * NMS-1000V https://www.planet.com.tw/en/product/nms-1000v
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11978 | WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials. |
Fri, 25 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Apr 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials. | |
| Title | Planet Technology Network Products Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-25T16:02:47.621Z
Reserved: 2025-04-22T15:31:46.237Z
Link: CVE-2025-46275
Updated: 2025-04-25T15:39:26.847Z
Status : Deferred
Published: 2025-04-24T23:15:15.977
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-46275
No data.
OpenCVE Enrichment
No data.
EUVD