Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://cert.pl/posts/2025/05/CVE-2025-3758 | third party advisory |
https://cert.pl/en/posts/2025/05/CVE-2025-3758 | third party advisory |