Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

NSFOCUS SecGate3600 Firewall Missing Authentication Vulnerability in Information Disclosure

Vulnerability

A vulnerability allowing sensitive information disclosure has been identified in the NSFOCUS SecGate3600 network firewall. This issue arises in the '/cgi-bin/authUser/authManageSet.cgi' endpoint, where the component fails to enforce proper authentication on POST requests. As a result, an unauthenticated remote attacker can exploit this vulnerability to access sensitive user data, including identifiers and configuration details, by sending crafted requests to the affected endpoint.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive user information and configuration details on the firewall.

Reproduction

To reproduce this vulnerability, send a POST request to the '/cgi-bin/authUser/authManageSet.cgi' endpoint without authentication. Include the 'type=getAllUsers' parameter in the request data. If the response contains user IDs, the vulnerability has been successfully exploited.

Added: Aug 27, 2025, 10:30 PM
Updated: Aug 27, 2025, 10:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.4
threat
8.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.