CVE-2025-3759

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
08/05/2025
Last modified:
08/05/2025

Description

Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing.<br /> The vendor was contacted early about this disclosure but did not respond in any way.