The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13995 | WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 03 Oct 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-311 |
Fri, 03 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-256 |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 08 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 May 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Exposure of Device Configuration without Authentication in WF2220 | |
| Weaknesses | CWE-306 CWE-311 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-10-03T08:57:29.206Z
Reserved: 2025-04-17T11:03:23.139Z
Link: CVE-2025-3758
Updated: 2025-05-08T13:47:10.807Z
Status : Awaiting Analysis
Published: 2025-05-08T10:15:18.017
Modified: 2025-10-03T09:15:37.933
Link: CVE-2025-3758
No data.
OpenCVE Enrichment
No data.
EUVD