An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000
Project Subscriptions
| Vendors | Products |
|---|---|
|
Wavlink
Subscribe
|
Jetstream Ac3000
Subscribe
Jetstream Ac3000 Firmware
Subscribe
Jetstream Erac3000
Subscribe
Jetstream Erac3000 Firmware
Subscribe
Wl-wn575a3
Subscribe
Wl-wn575a3 Firmware
Subscribe
Wl-wn579g3
Subscribe
Wl-wn579g3 Firmware
Subscribe
Wn530h4
Subscribe
Wn530h4 Firmware
Subscribe
Wn531a6
Subscribe
Wn531a6 Firmware
Subscribe
Wn535g3
Subscribe
Wn535g3 Firmware
Subscribe
Wn572hg3
Subscribe
Wn572hg3 Firmware
Subscribe
Wn575a4
Subscribe
Wn575a4 Firmware
Subscribe
Wn578a2
Subscribe
Wn578a2 Firmware
Subscribe
Wn579g3
Subscribe
Wn579g3 Firmware
Subscribe
Wn579x3
Subscribe
Wn579x3 Firmware
Subscribe
Wn57x93
Subscribe
Wn57x93 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-3373 | An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:21:14.401Z
Reserved: 2020-03-26T00:00:00
Link: CVE-2020-10974
No data.
Status : Modified
Published: 2020-05-07T18:15:11.333
Modified: 2024-11-21T04:56:29.563
Link: CVE-2020-10974
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD