Home
CRITICAL: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCRITICAL: 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:NDefault status
unaffected
Version R08
affected
Version V03
affected
Version V05
affected
Version V18
affected
Description
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.
Problem types
Product status
Version R08
Version V03
Version V05
Version V18
Credits
Abhishek Pandey from Payatu Security Consulting Pvt. Ltd. reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-317-08
github.com/...p/csaf_files/OT/white/2025/icsa-25-317-08.json