7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which
could allow an attacker to send GET requests to obtain sensitive device
information.
could allow an attacker to send GET requests to obtain sensitive device
information.
Basic Information
ID
CVE-2025-59780
Source
icscert
Published
Nov 14, 2025 at 23:26
Affected Product
Vendor
General Industrial Controls
Product
Lynx+ Gateway
Version
Version R08
Affected Versions
General Industrial Controls Lynx+ Gateway Version R08
General Industrial Controls Lynx+ Gateway Version V03
General Industrial Controls Lynx+ Gateway Version V05
General Industrial Controls Lynx+ Gateway Version V18
General Industrial Controls Lynx+ Gateway Version V03
General Industrial Controls Lynx+ Gateway Version V05
General Industrial Controls Lynx+ Gateway Version V18