CVE-2025-4558: Wormhole Tech Gpm
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
Affected products
- Wormhole Tech Gpm: before 202502 (fixed in 202502)
Published 2025-05-12. Last modified 2026-06-17.