CVE-2025-4558
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
12/05/2025
Last modified:
12/05/2025
Description
The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL



