Vulnerability Description
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Stengg | Vpncrypt M10 Firmware | 2.6.5 |
| Stengg | Vpncrypt M10 | - |
Related Weaknesses (CWE)
References
- https://www.stengg.com/cybersecurityThird Party Advisory
- https://www.stengg.com/media/1076253/vpncrypt-m10-cve-advisory-notice.pdfThird Party Advisory
- https://www.stengg.com/cybersecurityThird Party Advisory
- https://www.stengg.com/media/1076253/vpncrypt-m10-cve-advisory-notice.pdfThird Party Advisory
FAQ
What is CVE-2020-12106?
CVE-2020-12106 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Adminis...
How severe is CVE-2020-12106?
CVE-2020-12106 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-12106?
Check the references section above for vendor advisories and patch information. Affected products include: Stengg Vpncrypt M10 Firmware, Stengg Vpncrypt M10.