Hard-Coded Credentials Vulnerability in NuCom NC-WR744G Console Application
CVE-2025-5379
5.3MEDIUM
What is CVE-2025-5379?
A security issue has been identified in the NuCom NC-WR744G 8.5.5 Build 20200530.307 involving the Console Application. This vulnerability stems from improper handling of arguments in the component, specifically with the path CMCCAdmin/useradmin/CUAdmin, which exposes hard-coded credentials. Attackers can exploit this flaw remotely, gaining unauthorized access to sensitive system functions. Despite attempts to notify the vendor, there has been no response, emphasizing the importance of addressing this vulnerability urgently to protect users.
Affected Version(s)
NC-WR744G 8.5.5 Build 20200530.307