Description
Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to use the product as an intermediary for FTP bounce attack.
References (3)
Core 3
Core References
Various Sources
https://www.electronics.jtekt.co.jp/en/topics/202503207269/
Various Sources
https://www.electronics.jtekt.co.jp/en/topics/202503207271/
Third Party Advisory
https://jvn.jp/en/jp/JVN17260367/
Scores
CVSS v3
5.8
EPSS
0.0038
EPSS Percentile
29.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-441
Status
published
Products (2)
JTEKT ELECTRONICS CORPORATION/HMI GC-A2 series
All versions
JTEKT ELECTRONICS CORPORATION/HMI ViewJet C-more series
All versions
Published
Apr 04, 2025
Tracked Since
Feb 18, 2026