← back
CVE-2025-4558criticalCWE-620

WormHole Tech GPM - Unverified Password Change

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.3epss 0.5%
exploitation probability
0.5%top 58% of all CVEs
observed exploitation
nono source reports it
The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
WormHole Tech · GPM