VYPR

IP 4c Firmware

by 2wcom

CVEs (2)

  • CVE-2025-57438MedSep 22, 2025
    risk 0.44cvss 6.8epss 0.00

    The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants access to a manager-level account. However, a manager-level user can bypass these controls by…

  • CVE-2025-57433MedSep 22, 2025
    risk 0.42cvss 6.5epss 0.00

    The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a specific endpoint (/cwi/ajax_request/get_data.php), an authenticated attacker (even with a low-privileged account like guest) can retrieve the…