CVE-2024-25734: Wyrestorm Apollo VX20 Firmware

High severity, CVSS 7.5. EPSS: 4.1% chance of exploitation in the next 30 days.

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.

Affected products

  • Wyrestorm Apollo VX20 Firmware: before 1.3.58 (fixed in 1.3.58)

Published 2024-03-27. Last modified 2026-06-17.