Netis Systems Wf2220 vulnerabilities
2 known vulnerabilities affecting netis_systems/wf2220.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2025-3759P2HIGHCVSS 8.7Exploitedv1.2.317062025-05-08
CVE-2025-3759 [HIGH] CWE-306 CVE-2025-3759: Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible
Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing.
The vendor was contacted early about this disclosure but did not respond in any way.
nvd
CVE-2025-3758P3HIGHCVSS 8.7v1.2.317062025-05-08
CVE-2025-3758 [HIGH] CWE-256 CVE-2025-3758: WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to una
WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password.
The vendor was contacted early about this disclosure but did not respond in any way.
nvd