CVE-2025-3759: Missing Authentication for Changing Device Configuration in WF2220

Published May 8, 2025
·
Updated

Endpoint /cgi-bin-igd/netcoreset.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
Unknown WF2220

Event History

May 8, 2025
CVE Published
via MITRE·10:05 AM
Data Sourced
via MITRE·10:05 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-3759?

CVE-2025-3759 is considered a critical vulnerability due to its potential for unauthorized access and significant security threat to device configurations.

2

How do I fix CVE-2025-3759?

To fix CVE-2025-3759, implement access controls or authentication mechanisms on the /cgi-bin-igd/netcore_set.cgi endpoint.

3

What types of devices are affected by CVE-2025-3759?

CVE-2025-3759 affects devices such as the WF2220 that utilize the vulnerable endpoint for configuration changes.

4

What can attackers do if they exploit CVE-2025-3759?

If exploited, attackers can hijack administrator accounts and change access passwords for the access point.

5

Has a patch been released for CVE-2025-3759?

As of now, no official patch has been released for CVE-2025-3759, so users need to implement workarounds to mitigate the risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203