Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

CISA Alerts on Critical Lynx+ Gateway Flaw Leaks Data in Cleartext

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security alert regarding multiple vulnerabilities affecting General Industrial Controls’ Lynx+ Gateway device. Released on November 13, 2025, under alert code…

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security alert regarding multiple vulnerabilities affecting General Industrial Controls’ Lynx+ Gateway device. Released on November 13, 2025, under alert code ICSA-25-317-08, these flaws pose significant risks to industrial control systems. They could enable remote attackers to access sensitive information or disrupt critical operations. CVE IDVulnerability TypeCVSS v3 ScoreCVSS v4 ScoreCWE ReferenceCVE-2025-58083Missing Authentication for Critical Function10.09.2CWE-306 Vulnerability Overview The Lynx+ Gateway vulnerabilities encompass three distinct security weaknesses: weak password requirements, missing authentication for critical functions, and cleartext transmission of sensitive information. These combined flaws create a dangerous attack surface that threat actors can exploit with minimal effort. The most critical issue is the lack of authentication on the embedded web server, which allows attackers to reset the device without proper authorization remotely. CISA has assigned a CVSS v4 score of 9.2 to the primary vulnerability, indicating critical severity. The alert flags the attack as remotely exploitable and low in complexity, meaning adversaries require minimal resources or technical expertise to compromise affected devices. Successful exploitation could result in the acquisition of sensitive device information, unauthorized system access, or the creation of denial-of-service conditions that turn off critical industrial operations. The missing authentication vulnerability, designated CVE-2025-58083, carries a maximum severity CVSS v3 score of 10.0, the highest classification. This vulnerability affects the web server’s authentication controls, allowing unauthenticated remote actors to perform administrative functions without any access restrictions. The device reset capability alone could cause operational disruptions in industrial environments where unplanned downtime carries significant consequences. The cleartext transmission vulnerability enables attackers to intercept sensitive data in transit without encryption. Combined with weak password requirements, this creates a pathway for credential harvesting and unauthorized system access. Organizations running Lynx+ Gateway devices face elevated risk, particularly those connected to critical infrastructure networks. General Industrial Controls users are encouraged to check the CSAF advisories and official vendor security bulletins for specific patch availability and deployment guidance. This alert underscores the ongoing threats facing industrial control systems. It emphasizes the importance of timely vulnerability management in critical infrastructure environments. Follow us on Google News, LinkedIn, and X to Get Instant Updates and set GBH as a Preferred Source in Google.

Based on reporting by GBHackers.

Released on November 13, 2025, under alert code ICSA-25-317-08, these flaws pose significant risks to industrial control systems.
Brian Shaw · Thehackingpost
Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories