CRITICAL
Planet Technology|Industrial Cellular Gateway - Missing Authentication
Published Sep 17, 2025
9.3
CRITICALCVSS 4.0
EPSS 0.83%
Description
Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a specific functionality.
Affected products
-
- Version 0StatusaffectedConstraints<=1.0_20240411
- Version
-
- Version 0StatusaffectedConstraints<=1.0-20240918
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Planet Technology | Icg-2510w-Lte (eu/us) | unaffected |
| ||||||
| Planet Technology | Icg-2510wg-Lte (eu/us) | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update ICG-2510WG-LTE (EU/US) to version V1.0_20250811 or later Update ICG-2510W-LTE (EU/US) to version V1.0_20250811 or later
Weaknesses (1)
References (3)
- https://www.planet.com.tw/en/support/security-advisory/8 vendor-advisory
- https://www.twcert.org.tw/en/cp-139-10390-7ce12-2.html third-party-advisory
- https://www.twcert.org.tw/tw/cp-132-10389-265a3-1.html third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.planet.com.tw/en/support/security-advisory/8 | vendor-advisory | |
| https://www.twcert.org.tw/en/cp-139-10390-7ce12-2.html | third-party-advisory | |
| https://www.twcert.org.tw/tw/cp-132-10389-265a3-1.html | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Sep 17, 2025
Updated Sep 17, 2025
Reserved Sep 4, 2025
Link CVE-2025-9971
CISA Vulnrichment
Updated Sep 17, 2025