CVE-2025-4010 - CVE House
Back to Database
Status published High CVE-2025-4010

Arbitrary Command Injection in Netcom NTC-6200 & NWL-222

Vulnerability Description

The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoints of the web interface are vulnerable to arbitrary command injection and use insecure hardcoded passwords. Remote authenticated attackers can gain arbitrary code execution with elevated privileges.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4010

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • ONEKEY Research Labs

Affected Vendor

Affected Software

NTC 6200, NWL-222
Vulnerable Versions:
0

Timeline

Official Publish: June 2nd, 2025
Last Modified: June 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)