The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version V108_108 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 27 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pix-link
Pix-link lv-wr21q |
|
| Vendors & Products |
Pix-link
Pix-link lv-wr21q |
Tue, 27 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticated attacker is able to use this endpoint to e.g: retrieve cleartext password to the access point. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version V108_108 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. | |
| Title | Missing Authentication for Critical Endpoint in Pix-Link LV-WR21Q | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-01-27T13:37:44.492Z
Reserved: 2025-10-28T12:02:30.410Z
Link: CVE-2025-12386
Updated: 2026-01-27T13:37:25.002Z
Status : Awaiting Analysis
Published: 2026-01-27T12:15:56.473
Modified: 2026-01-27T14:59:34.073
Link: CVE-2025-12386
No data.
OpenCVE Enrichment
Updated: 2026-01-27T20:16:29Z