PT-2025-20372 · Netis Systems · Wf2220

Kamil Szczurowski

·

Published

2025-05-08

·

Updated

2025-05-08

·

CVE-2025-3759

CVSS v4.0

8.7

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description The endpoint /cgi-bin-igd/netcore set.cgi is used for changing device configuration and is accessible without authentication, posing a significant security threat. This could allow for administrator account hijacking or AP password changing. The vendor was contacted about this disclosure but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-3759

Affected Products

Wf2220