CVE-2024-25734: Wyrestorm Apollo VX20 Firmware
High severity, CVSS 7.5. EPSS: 4.1% chance of exploitation in the next 30 days.
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.
Affected products
- Wyrestorm Apollo VX20 Firmware: before 1.3.58 (fixed in 1.3.58)
Published 2024-03-27. Last modified 2026-06-17.