CVE Database
/

CVE-2025-3659

Back to search

CVE-2025-3659

Published: May 12, 2025

Modified: May 12, 2025

PUBLISHED

Description

Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020 * Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020 A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.

VendorProductVersions

Digi International

Digi PortServer TS

affected
0 - <= 82000747_AA

Digi International

Digi One SP/Digi One SP IA/Digi One IA

affected
0 - <= 82000774_Z

Digi International

Digi One IAP

affected
0 - <= 82000770 Z

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now