Description
Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to use the product as an intermediary for FTP bounce attack.
Scores
CVSS v3
5.8
EPSS
0.0012
EPSS Percentile
30.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-441
Status
published
Products (2)
JTEKT ELECTRONICS CORPORATION/HMI GC-A2 series
All versions
JTEKT ELECTRONICS CORPORATION/HMI ViewJet C-more series
All versions
Published
Apr 04, 2025
Tracked Since
Feb 18, 2026