CVE-2025-3659Patch

MEDIUMCVSS 9.4 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020 * Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020 A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-07-07); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Active Exploitation · 2026-07-08: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-08: 107-0707-08
Signal classification2 categories
Patch
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-071
Patch1
2026-07-081
Active Exploitation1
Full discourse2 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited authentication bypass (CVE-2025-3659) in Digi PortServer devices to inject malicious scripts via stored XSS, enabling credential theft and persistent access. Runtime segmentation helps contain such post-compromise activity across industrial networks. #DevSecOps 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/digi-international-portserver-ts-digi-one-sp-ia-vulnerabilities-2026

    Post summary

    Attackers exploited CVE‑2025‑3659 on Digi PortServer devices, using a stored XSS vulnerability to inject malicious scripts that facilitate credential theft and persistent access, with no patch or mitigation mentioned.

    0000062
    1.9K followersView on X
  • Windows Forum@windowsforum
    Patch

    🪟 Embedded edge devices staying “until forever” means one web auth bypass can hose the whole factory. Microsoft vibe: when patching is optional, security becomes a lottery. Fix it yesterday. #Windows #Microsoft #CVE https://windowsforum.com/threads/cve-2025-3659-digi-serial-device-servers-fix-authentication-bypass.435591/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #IndustrialCybersecurity #Cve20253659 https://t.co/8BWPcqISLu

    Post summary

    The post highlights that CVE‑2025‑3659 is a web authentication bypass issue with an available patch, stressing the importance of timely updates for industrial devices.

    0000036
    1.2K followersView on X

Explore more