Vulnerability Description
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juplink | Rx4-1500 Firmware | 1.0.4 |
| Juplink | Rx4-1500 | - |
Related Weaknesses (CWE)
References
- https://blog.exodusintel.com/2023/09/18/juplink-rx4-1500-credential-disclosure-vThird Party Advisory
- https://blog.exodusintel.com/2023/09/18/juplink-rx4-1500-credential-disclosure-vThird Party Advisory
FAQ
What is CVE-2023-41027?
CVE-2023-41027 is a vulnerability with a CVSS score of 8.0 (HIGH). Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administr...
How severe is CVE-2023-41027?
CVE-2023-41027 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-41027?
Check the references section above for vendor advisories and patch information. Affected products include: Juplink Rx4-1500 Firmware, Juplink Rx4-1500.