CVE-2025-3659 is a low severity vulnerability with a CVSS score of 0.0. No known public exploits at this time.
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.
Very low probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families:
Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022
Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020
Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020
A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.