An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege escalation and denial of service.
References
Configurations
No configuration.
History
09 Jan 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-306 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
08 Jan 2026, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-08 20:15
Updated : 2026-01-09 19:16
NVD link : CVE-2025-68715
Mitre link : CVE-2025-68715
CVE.ORG link : CVE-2025-68715
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
