CVE-2025-68717Patch(kaysus / ks-wr3600)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kaysus ks-wr3600 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user's active session to retrieve sensitive configuration data or execute privileged actions without authentication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ks-wr3600
  • ks-wr3600_firmware

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ks-wr3600ks-wr3600_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-03: 1Patch / Workaround · 2026-08-03: 108-03
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • المحارب🏆🇦🇪🇪🇬@nike49424
    Patch

    @cybersecurity 🔥 عينة لأبرز 5 ثغرات مفهرسة ومرفقة بالحلول من داخل التقرير: 1. CVE-2025-13952 (مرفق معها ترقيع برلمجي C++ Patch) 2. CVE-2025-68717 (مرفق معها وثيقة ZayedShield Doc) 3. CVE-2026-25761 (تحليل أمني متقدم لعام 2026) 4. CVE-2025-55182 (تأمين الخدمات البنيوية) 5. CVE-2026-21440 (بلاغ

    Post summary

    The tweet lists five CVEs, highlighting a C++ patch for CVE-2025-13952 and additional documentation for the others, but contains no PoC, exploit details, or active exploitation claims.

    0000048
    52 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWkaysusks-wr3600---
OSkaysusks-wr3600_firmware1.0.5.9.1--

Explore more