CVE-2025-55034
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-521
- Published
- 2025-11-14
- Last modified
- 2026-03-12
Affected products
- General Industrial Controls Lynx+ Gateway
- General Industrial Controls Lynx+ Gateway
- General Industrial Controls Lynx+ Gateway
- General Industrial Controls Lynx+ Gateway
Weakness type
Related vulnerabilities
- CVE-2026-85216 — MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
- CVE-2026-19293 — SMP security request
- CVE-2026-12504 — Loytec LINX firmware: Improper Authentication in PAM configuration
- CVE-2026-56577 — HCL MyCloud affected by Weak Password Policy
- CVE-2026-35097 — Weak Password Requirements in KTM System e-BOK
- CVE-2026-11493 — Tenda AC15 Samba smb.conf weak password
- CVE-2024-40684 — IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout Mechanism
- CVE-2026-9394 — Besen BS20 EV Charging Station Bluetooth Low Energy weak password