CVE-2025-3759
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
08/05/2025
Last modified:
08/05/2025
Description
Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing.<br />
The vendor was contacted early about this disclosure but did not respond in any way.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH