Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pc6g-gmrw-x724

Опубликовано: 08 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege escalation and denial of service.

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege escalation and denial of service.

EPSS

Процентиль: 60%
0.00404
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.1
nvd
около 1 месяца назад

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege escalation and denial of service.

EPSS

Процентиль: 60%
0.00404
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-306
Уязвимость GHSA-pc6g-gmrw-x724