CVE-2025-59780 - CVE House
Back to Database
Status published High CVE-2025-59780

General Industrial Controls Lynx+ Gateway Missing Authentication for Critical Function

Vulnerability Description

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59780

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Abhishek Pandey from Payatu Security Consulting Pvt. Ltd. reported these vulnerabilities to CISA.

Affected Vendor

General Industrial Controls

View all reports →

Affected Software

Lynx+ Gateway
Vulnerable Versions:
Version R08, Version V03, Version V05, Version V18

Timeline

Official Publish: November 14th, 2025
Last Modified: November 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)