CVE detail
CVE-2024-25734 — CVE-2024-25734
Published 2024-03-27 · Modified 2026-06-17 · Vendor wyrestorm · Product apollo_vx20_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0405
EPSS probability
exploitation probability, 30d
90.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References