CVE-2025-0630 describes a Local File Inclusion (LFI) vulnerability present in the web interface of multiple Western Telematic (WTI) products, allowing any authenticated user to access files on the device's filesystem. Rated Medium severity (CVSS 6.5), this vulnerability can be exploited remotely with low complexity by an authenticated user, leading to high confidentiality impact without affecting integrity or availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Western Telematic Inc | Console Server (DSM Series) | >= 0, <= 6.62CNA affecteddefault unaffected | |
| Western Telematic Inc | Console Server + PDU Combo Unit (CPM Series) | >= 0, <= 6.62CNA affecteddefault unaffected | |
| Western Telematic Inc | Network Power Switch (NPS Series) | >= 0, <= 6.62CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.