9.8
CVE-2025-63218
- EPSS 0.96%
- Veröffentlicht 19.11.2025 00:00:00
- Zuletzt bearbeitet 12.01.2026 16:01:06
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system settings, leading to full compromise of the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Axeltechnology ≫ Wolf1ms Firmware Version >= 0.8.5 <= 1.0.3
Axeltechnology ≫ Wolf2ms Firmware Version >= 0.8.5 <= 1.0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.96% | 0.76 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.