Junglewise Threat Intelligence

CVE-2025-45422: Proximus b-box 3 access control bypass in UPnP

CVE-2025-45422 · Severity: info · CVSS 8.8 · Published 2026-07-09

Executive brief

A security flaw in the Proximus b-box 3 home router allows unauthorized users on the local network to bypass security controls and modify port forwarding rules. This could allow an attacker to expose internal devices to the public internet, potentially leading to unauthorized access to home computers or smart devices. Furthermore, these malicious changes cannot be permanently deleted through the router's standard management interface, allowing an attacker to maintain persistent access to the network.

Technical details

An incorrect access control vulnerability exists in the UPnP implementation of Proximus b-box 3 routers running firmware version 8c.725A. The flaw allows an attacker with local network access to issue UPnP commands to create arbitrary port mappings for any local IP address, bypassing the restrictions of the web management interface. A critical aspect of this vulnerability is that the router's GUI only allows users to disable, rather than permanently delete, these mappings, while the UPnP service remains active and cannot be fully disabled. This allows an attacker to re-enable disabled rules at any time, achieving persistence. Additionally, attackers can use the NewLeaseDuration parameter to create temporary mappings that expire automatically to evade detection.

Affected products

  • Proximus b-box 3 8c.725A

Timeline

  • 2026-07-09: disclosed

References