CVE-2025-3759

CVSS

No CVSS.

E

ndpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.

Configurations

No configuration.

History

08 May 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-08 10:15

Updated : 2025-05-08 14:39


NVD link : CVE-2025-3759

Mitre link : CVE-2025-3759

CVE.ORG link : CVE-2025-3759


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function