WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password.
The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 08 May 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Exposure of Device Configuration without Authentication in WF2220 | |
Weaknesses | CWE-306 CWE-311 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-05-08T10:05:00.716Z
Updated: 2025-05-08T13:48:47.390Z
Reserved: 2025-04-17T11:03:23.139Z
Link: CVE-2025-3758

Updated: 2025-05-08T13:47:10.807Z

Status : Awaiting Analysis
Published: 2025-05-08T10:15:18.017
Modified: 2025-05-08T14:39:09.683
Link: CVE-2025-3758

No data.