Abhishek Pandey

8 exploits Active since Nov 2025
CVE-2026-24455 WRITEUP HIGH WRITEUP
Device Web Interface - Info Disclosure
The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.
CVSS 7.5
CVE-2026-25715 WRITEUP CRITICAL WRITEUP
Device Web Interface - Auth Bypass
The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permits authentication with empty credentials over the web management interface and Telnet service. This effectively disables authentication across all critical management channels, allowing any network-adjacent attacker to gain full administrative control without credentials.
CVSS 9.8
CVE-2026-26048 WRITEUP HIGH WRITEUP
Wi-Fi Router - DoS
The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing forged deauthentication and disassociation frames to be broadcast without authentication or encryption. An attacker can use this to cause unauthorized disruptions and create a denial-of-service condition.
CVSS 7.5
CVE-2026-26049 WRITEUP MEDIUM WRITEUP
Device Web Interface - Info Disclosure
The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone with access to the UI, potentially exposing administrator credentials to unauthorized observation via shoulder surfing, screenshots, or browser form caching.
CVSS 5.7
CVE-2025-55034 WRITEUP HIGH WRITEUP
General Industrial Controls Lynx+ Gateway - Info Disclosure
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.
CVSS 8.2
CVE-2025-58083 WRITEUP CRITICAL WRITEUP
General Industrial Controls Lynx+ Gateway - Auth Bypass
General Industrial Controls Lynx+ Gateway  is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.
CVSS 10.0
CVE-2025-59780 WRITEUP HIGH WRITEUP
Lynx+ Gateway - Info Disclosure
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information.
CVSS 7.5
CVE-2025-62765 WRITEUP HIGH WRITEUP
General Industrial Controls Lynx+ Gateway - Info Disclosure
General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials.
CVSS 7.5