CVE-2025-2920
LOWNetis WF-2404 1.1.124EN - Weak Hash
Title source: llmDescription
A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This issue affects some unknown processing of the file /еtc/passwd. The manipulation leads to use of weak hash. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scores
CVSS v3
2.0
EPSS
0.0004
EPSS Percentile
13.3%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-327
CWE-328
Status
draft
Timeline
Published
Mar 28, 2025
Tracked Since
Feb 18, 2026