{"id":8525,"date":"2025-11-18T10:03:31","date_gmt":"2025-11-18T10:03:31","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/18\/cisa-warns-of-critical-lynx-gateway-vulnerability-exposes-data-in-cleartext\/"},"modified":"2025-11-18T10:03:31","modified_gmt":"2025-11-18T10:03:31","slug":"cisa-warns-of-critical-lynx-gateway-vulnerability-exposes-data-in-cleartext","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/18\/cisa-warns-of-critical-lynx-gateway-vulnerability-exposes-data-in-cleartext\/","title":{"rendered":"CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext"},"content":{"rendered":"<p>    CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about a severe vulnerability in Lynx+ Gateway devices that could expose sensitive information in clear text during transmission.<\/p>\n<p>The flaw allows attackers to catch network traffic and obtain <a href=\"https:\/\/cybersecuritynews.com\/windows-wdigest-authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">plaintext credentials<\/a> and other confidential data. The vulnerability, tracked as CVE-2025-62765, stems from the product\u2019s failure to encrypt data during transmission.<\/p>\n<p>This cleartext transmission vulnerability poses a significant security risk for organizations that rely on Lynx+ Gateway technology, particularly those managing critical infrastructure or handling sensitive communications.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-lynx-gateway-vulnerability\"><strong>Lynx+ Gateway Vulnerability<\/strong><\/h2>\n<p>An attacker with network access could exploit this weakness by monitoring traffic flowing through the affected gateway.<\/p>\n<p>The lack of encryption means that credentials,<a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-customer-authentication-tokens\/\" target=\"_blank\" rel=\"noreferrer noopener\"> authentication tokens<\/a>, and other sensitive information transmitted across the network remain visible to potential threat actors.<\/p>\n<p>According to CISA, no authentication or user interaction is required to launch an attack, making this vulnerability particularly dangerous.<\/p>\n<p>The vulnerability has received a CVSS v3 base score of 7.5, indicating a high-severity threat.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>Product<\/th>\n<th>Vulnerability Type<\/th>\n<th>CVSS v3 Score<\/th>\n<th>CVSS v4 Score<\/th>\n<th>Impact<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-62765\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2025-62765<\/a><\/td>\n<td>Lynx+ Gateway<\/td>\n<td>Cleartext Transmission<\/td>\n<td>7.5 (High)<\/td>\n<td>8.7 (Critical)<\/td>\n<td>Plaintext Credentials &amp; Data Exposure<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>The CVSS v3 vector string (AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A: N) shows the attack can be executed remotely with low complexity and requires no privileges.<\/p>\n<p>The vulnerability severely impacts confidentiality without affecting integrity or availability. The CVSS v4 score is even more severe at 8.7, reflecting the evolving assessment of this threat.<\/p>\n<p>The CVSS v4 vector (AV:N\/AC:L\/AT:N\/PR:N\/UI:N\/VC:H\/VI:N\/VA:N\/SC:N\/SI:N\/SA: N) confirms that the attack vector remains network-based, with minimal barriers to exploitation.<\/p>\n<p>Organizations using Lynx+ Gateway devices should prioritize<a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-federal-agencies\/\"> patching <\/a>this vulnerability immediately. CISA <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-317-08\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">recommends<\/a> implementing network segmentation to limit exposure and monitoring for suspicious network activity.<\/p>\n<p>Additionally, organizations should consider implementing encrypted communication channels and reviewing access logs for signs of unauthorized traffic interception.<\/p>\n<p>Until patches are available, administrators should restrict network access to affected gateways and implement additional <a href=\"https:\/\/cybersecuritynews.com\/best-digital-footprint-monitoring-tools-for-organizations\/\" target=\"_blank\" rel=\"noreferrer noopener\">monitoring controls<\/a>.<\/p>\n<p>Given the critical nature of this flaw, this update should be treated as a high-priority security incident requiring urgent attention from network and security teams.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/lynx-gateway-vulnerability\/\">CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/lynx-gateway-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about a severe vulnerability in Lynx+ Gateway devices that could expose sensitive information in clear text during transmission. The flaw allows attackers to catch network traffic and obtain plaintext credentials and other [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-8525","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8525"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8525"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8525\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}