CVE-2025-68717
Last modified
CVE-2025-68717 is a critical-severity vulnerability rated 9.4/10 on the CVSS scale. KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user's active session to retrieve sensitive configuration data or execute privileged actions without authentication.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kaysus | Ks-Wr3600 Firmware | 1.0.5.9.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-68717?
How severe is CVE-2025-68717?
How do I fix CVE-2025-68717?
Are you affected by CVE-2025-68717?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
