CVE-2025-1907 Details
Description
Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if connected.
A vulnerability exists in the Instantel Micromate due to a lack of authentication on a configuration port. This flaw could enable an unauthenticated attacker to execute commands on the device if connected. All versions of the Micromate are affected.
Instantel is working on a firmware update to address this vulnerability. In the meantime, users are advised to maintain a list of approved IP addresses allowed to access the modem to prevent unauthorized access. For more information, contact Instantel technical support.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 30, 2025CISA-ADP
Assessed May 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Instantel Micromate | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 30, 2025 | New CVE Received | [email protected] |
Volerion