CVE-2025-3659: Digi International Digi One Iap
Critical severity, CVSS 9.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020 * Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020 A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.
Affected products
- Digi International Digi One Iap: up to and including 82000770 Z
- Digi International Digi One Sp/digi One SP Ia/digi One Ia: up to and including 82000774_Z
- Digi International Digi Portserver Ts: up to and including 82000747_AA
Published 2025-05-12. Last modified 2026-06-17.