CVE Vulnerabilities

CVE-2025-3758

Plaintext Storage of a Password

Published: May 08, 2025 | Modified: Oct 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Potential Mitigations

References