CVE Database
/

CVE-2025-4010

Back to search

CVE-2025-4010

Published: Jun 2, 2025

Modified: Jun 2, 2025

PUBLISHED

Description

The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoints of the web interface are vulnerable to arbitrary command injection and use insecure hardcoded passwords. Remote authenticated attackers can gain arbitrary code execution with elevated privileges.

VendorProductVersions

Netcomm

NTC 6200

affected
0

Netcomm

NWL-222

affected
0 - < 2.1.21.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now