CVE-2025-3759: Missing Authentication for Changing Device Configuration in WF2220
Endpoint /cgi-bin-igd/netcoreset.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3759?
CVE-2025-3759 is considered a critical vulnerability due to its potential for unauthorized access and significant security threat to device configurations.
How do I fix CVE-2025-3759?
To fix CVE-2025-3759, implement access controls or authentication mechanisms on the /cgi-bin-igd/netcore_set.cgi endpoint.
What types of devices are affected by CVE-2025-3759?
CVE-2025-3759 affects devices such as the WF2220 that utilize the vulnerable endpoint for configuration changes.
What can attackers do if they exploit CVE-2025-3759?
If exploited, attackers can hijack administrator accounts and change access passwords for the access point.
Has a patch been released for CVE-2025-3759?
As of now, no official patch has been released for CVE-2025-3759, so users need to implement workarounds to mitigate the risk.