CRITICAL · 9.8

CVE-2020-12106

The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Adminis...

Vulnerability Description

The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
StenggVpncrypt M10 Firmware2.6.5
StenggVpncrypt M10-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-12106?

CVE-2020-12106 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Adminis...

How severe is CVE-2020-12106?

CVE-2020-12106 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-12106?

Check the references section above for vendor advisories and patch information. Affected products include: Stengg Vpncrypt M10 Firmware, Stengg Vpncrypt M10.