PT-2026-1917 · Panda Wireless · Panda Wireless Pwru0
Published
2026-01-08
·
Updated
2026-01-09
·
CVE-2025-68715
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Panda Wireless PWRU0 version 2.2.9
Description
An issue exists in Panda Wireless PWRU0 devices that exposes multiple HTTP endpoints without authentication. These endpoints include '/goform/setWan', '/goform/setLan', and '/goform/wirelessBasic'. A remote, unauthenticated attacker can modify WAN, LAN, and wireless settings directly, potentially leading to privilege escalation and denial of service.
Recommendations
For Panda Wireless PWRU0 version 2.2.9, restrict access to the HTTP endpoints '/goform/setWan', '/goform/setLan', and '/goform/wirelessBasic' to authenticated users only.
Exploit
Fix
LPE
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Panda Wireless Pwru0