CVE-2025-3659 describes an improper authentication vulnerability in Digi PortServer TS, Digi One SP/SP IA/IA, and Digi One IAP devices, allowing an unauthenticated attacker to modify configuration settings via a specially crafted HTTP POST request to the web interface. This critical vulnerability, rated 9.4 CVSS, has a low attack complexity and can lead to high impacts on confidentiality, integrity, and availability. While no active exploitation or public exploit code is currently known, and community discussion is minimal, the high FAUCET Risk Score of 86/100 indicates significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Digi International | Digi One IAP | >= 0, <= 82000770 ZCNA affecteddefault affected | |
| Digi International | Digi One SP/Digi One SP IA/Digi One IA | >= 0, <= 82000774_ZCNA affecteddefault affected | |
| Digi International | Digi PortServer TS | >= 0, <= 82000747_AACNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.