PT-2026-1917 · Panda Wireless · Panda Wireless Pwru0
CVE-2025-68715
·
Publicado
2026-01-08
·
Atualizado
2026-01-09
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Panda Wireless PWRU0 version 2.2.9
Description
An issue exists in Panda Wireless PWRU0 devices that exposes multiple HTTP endpoints without authentication. These endpoints include '/goform/setWan', '/goform/setLan', and '/goform/wirelessBasic'. A remote, unauthenticated attacker can modify WAN, LAN, and wireless settings directly, potentially leading to privilege escalation and denial of service.
Recommendations
For Panda Wireless PWRU0 version 2.2.9, restrict access to the HTTP endpoints '/goform/setWan', '/goform/setLan', and '/goform/wirelessBasic' to authenticated users only.
Exploit
Correção
LPE
DoS
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Panda Wireless Pwru0