Description
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000
Published: 2020-05-07
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-3373 An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000
History

No history.

Subscriptions

Wavlink Jetstream Ac3000 Jetstream Ac3000 Firmware Jetstream Erac3000 Jetstream Erac3000 Firmware Wl-wn575a3 Wl-wn575a3 Firmware Wl-wn579g3 Wl-wn579g3 Firmware Wn530h4 Wn530h4 Firmware Wn531a6 Wn531a6 Firmware Wn535g3 Wn535g3 Firmware Wn572hg3 Wn572hg3 Firmware Wn575a4 Wn575a4 Firmware Wn578a2 Wn578a2 Firmware Wn579g3 Wn579g3 Firmware Wn579x3 Wn579x3 Firmware Wn57x93 Wn57x93 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T11:21:14.401Z

Reserved: 2020-03-26T00:00:00.000Z

Link: CVE-2020-10974

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-07T18:15:11.333

Modified: 2024-11-21T04:56:29.563

Link: CVE-2020-10974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses