PT-2026-1917 · Panda Wireless · Panda Wireless Pwru0

Published

2026-01-08

·

Updated

2026-01-09

·

CVE-2025-68715

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Panda Wireless PWRU0 version 2.2.9
Description An issue exists in Panda Wireless PWRU0 devices that exposes multiple HTTP endpoints without authentication. These endpoints include '/goform/setWan', '/goform/setLan', and '/goform/wirelessBasic'. A remote, unauthenticated attacker can modify WAN, LAN, and wireless settings directly, potentially leading to privilege escalation and denial of service.
Recommendations For Panda Wireless PWRU0 version 2.2.9, restrict access to the HTTP endpoints '/goform/setWan', '/goform/setLan', and '/goform/wirelessBasic' to authenticated users only.

Exploit

Fix

LPE

DoS

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-68715

Affected Products

Panda Wireless Pwru0