Western Telematic Inc NPS Series, DSM Series, CPM Series External Control of File Name or Path
Vulnerability Description
Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged access to files on the device's filesystem.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0630
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- notnotnotveg (notnotnotveg@gmail.com) reported this vulnerability to CISA.
Affected Vendor
Western Telematic Inc
View all reports →