Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 08 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 May 2025 10:15:00 +0000

Type Values Removed Values Added
Description Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.
Title Missing Authentication for Changing Device Configuration in WF2220
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2025-05-08T10:05:07.131Z

Updated: 2025-05-08T13:40:38.421Z

Reserved: 2025-04-17T11:03:24.091Z

Link: CVE-2025-3759

cve-icon Vulnrichment

Updated: 2025-05-08T13:40:28.229Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-08T10:15:18.213

Modified: 2025-05-08T14:39:09.683

Link: CVE-2025-3759

cve-icon Redhat

No data.