could allow an attacker to send GET requests to obtain sensitive device
information.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
General Industrial Controls (GIC) did not respond to CISA's attempts to coordinate. Users of General Industrial Controls Lynx+ Gateway are encouraged to reach out to GIC for more information.
Mon, 17 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
General Industrial Controls
General Industrial Controls lynx+ Gateway |
|
| Vendors & Products |
General Industrial Controls
General Industrial Controls lynx+ Gateway |
Fri, 14 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information. | |
| Title | General Industrial Controls Lynx+ Gateway Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-11-17T16:54:08.683Z
Reserved: 2025-11-06T20:44:49.360Z
Link: CVE-2025-59780
Updated: 2025-11-17T16:49:10.920Z
Status : Awaiting Analysis
Published: 2025-11-15T00:15:47.313
Modified: 2025-11-18T14:06:55.963
Link: CVE-2025-59780
No data.
OpenCVE Enrichment
Updated: 2025-11-15T22:07:36Z