CVE-2025-59780 PUBLISHED

General Industrial Controls Lynx+ Gateway Missing Authentication for Critical Function

Assigner: icscert
Reserved: 06.11.2025 Published: 14.11.2025 Updated: 17.11.2025

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor General Industrial Controls
Product Lynx+ Gateway
Versions Default: unaffected
  • Version Version R08 is affected
  • Version Version V03 is affected
  • Version Version V05 is affected
  • Version Version V18 is affected

Workarounds

General Industrial Controls (GIC) did not respond to CISA's attempts to coordinate. Users of General Industrial Controls Lynx+ Gateway are encouraged to reach out to GIC for more information.

Credits

  • Abhishek Pandey from Payatu Security Consulting Pvt. Ltd. reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-306 CWE