HIGH · 7.5

CVE-2020-10974

An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is...

Vulnerability Description

An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
WavlinkWl-Wn575A3 Firmwarerpt75a3.v4300.180801
WavlinkWl-Wn575A3-
WavlinkWl-Wn579G3 Firmwarem79x3.v5030.180719
WavlinkWl-Wn579G3-
WavlinkWn531A6 Firmware-
WavlinkWn531A6-
WavlinkWn535G3 Firmware-
WavlinkWn535G3-
WavlinkWn530H4 Firmware-
WavlinkWn530H4-
WavlinkWn57X93 Firmware-
WavlinkWn57X93-
WavlinkWn572Hg3 Firmware-
WavlinkWn572Hg3-
WavlinkWn575A4 Firmware-
WavlinkWn575A4-
WavlinkWn578A2 Firmware-
WavlinkWn578A2-
WavlinkWn579G3 Firmware-
WavlinkWn579G3-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-10974?

CVE-2020-10974 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is...

How severe is CVE-2020-10974?

CVE-2020-10974 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-10974?

Check the references section above for vendor advisories and patch information. Affected products include: Wavlink Wl-Wn575A3 Firmware, Wavlink Wl-Wn575A3, Wavlink Wl-Wn579G3 Firmware, Wavlink Wl-Wn579G3, Wavlink Wn531A6 Firmware.