CVE-2025-58083

CRITICAL

General Industrial Controls Lynx+ Gateway  is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.

Affects 0 products across 2 vendors.

BCS6.48
CVSS 3.110.0
CVSS v49.2
EPSS0.6%
Percentile47th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-306: Missing Authentication for Critical Function

Software does not perform any authentication for functionality that requires a verified identity.

Related Attack Patterns (CAPEC)
CAPEC-12 Choosing Message Identifier
via CWE-306
CAPEC-36 Using Unpublished Interfaces or Functionality
via CWE-306
CAPEC-62 Cross Site Request Forgery
via CWE-306
CAPEC-166 Force the System to Reset Values
via CWE-306
CAPEC-216 Communication Channel Manipulation
via CWE-306

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The General Industrial Controls Lynx+ Gateway is vulnerable to unauthorized remote access due to a missing critical authentication mechanism in its embedded web server, allowing attackers to reset the device remotely.

BSID: BS-2025-GLOBAL-305802-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-58083?
The General Industrial Controls Lynx+ Gateway is vulnerable to unauthorized remote access due to a missing critical authentication mechanism in its embedded web server, allowing attackers to reset the device remotely.
What is the CVSS score for CVE-2025-58083?
CVE-2025-58083 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.6%.
Is CVE-2025-58083 actively exploited?
No confirmed active exploitation of CVE-2025-58083 as of 2026-05-30.
How do I remediate CVE-2025-58083?
Priority: IMMEDIATE. Advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-25-317-08
What systems are affected by CVE-2025-58083?
CVE-2025-58083 affects: Gateway, Lynx.
Vulnerability Details
CVE IDCVE-2025-58083
BSIDBS-2025-GLOBAL-305802-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2025-11-15
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

General Industrial Controls Lynx+ Gateway  is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by sending specially crafted HTTP requests to the embedded web server of the Lynx+ Gateway. The lack of proper authentication allows the attacker to perform actions such as resetting the device without authorization.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Gateway —
Lynx —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 264 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash7bb9ce50cf8679910a8196bf2981d26eaf1a9d7617dd2d7ad6275a8a7867ab70263169e8aaf794db5fa407370d906b766f76f6ae2cf652092f793672d0de332f
Related CVEs affecting Gateway
CVE-2024-50494 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Su... CVE-2025-41243 10.0 Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment p... CVE-2002-1440 10.0 The Gateway GS-400 server has a default root password of "0001n" that can not... CVE-2026-32621 9.9 Apollo Federation is an architecture for declaratively composing APIs into a ... CVE-2026-1868 9.9 GitLab has remediated a vulnerability in the Duo Workflow Service component o...
View all Gateway CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →