CVE-2025-36754

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.

Scoring

Severity
CRITICAL
CVSS base score
9.3
CVSS vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H
EPSS probability
0.18%
CWE
CWE-290
Published
2025-12-13
Last modified
2026-03-13

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs