TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-68717

CRITICAL
9.4

Beschreibung

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user's active session to retrieve sensitive configuration data or execute privileged actions without authentication.

CVE Details

CVSS v3.1 Bewertung9.4
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht1/8/2026
Zuletzt geandert2/2/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

kaysus:ks-wr3600kaysus:ks-wr3600_firmware

Schwachen (CWE)

CWE-287

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.