# CVE-2025-4558

## Summary

- **CVE ID:** CVE-2025-4558
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-620
- **Published:** May 12, 2025
- **Last Modified:** Mar 13, 2026

## Description

The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.

## Affected Products

- WormHole Tech — GPM (0)

## References

- [CNA](https://www.twcert.org.tw/tw/cp-132-10114-10b4b-1.html)
- [CNA](https://www.twcert.org.tw/en/cp-139-10115-f5f14-2.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.51%
- **EPSS Percentile:** 41.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._