CVE-2025-3758
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
08/05/2025
Last modified:
08/05/2025
Description
WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password.<br />
The vendor was contacted early about this disclosure but did not respond in any way.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH