CVE-2025-3758

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
08/05/2025
Last modified:
08/05/2025

Description

WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password.<br /> The vendor was contacted early about this disclosure but did not respond in any way.