CVE-2025-52376

An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassing security controls. The Telnet server is then accessible with hard-coded credentials, allowing attackers to gain administrative shell access and execute arbitrary commands on the device.
Configurations

No configuration.

History

15 Jul 2025, 20:07

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-15 14:15

Updated : 2025-07-15 20:07


NVD link : CVE-2025-52376

Mitre link : CVE-2025-52376

CVE.ORG link : CVE-2025-52376


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-798

Use of Hard-coded Credentials