An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can be accessed externally without any authentication. All the pages follow the naming convention live_(string).shtml. Among the information disclosed is: interface status logs, IP address of the device, MAC address of the device, model and current firmware version, location, all running processes, all interfaces and their statuses, all current DHCP leases and the associated hostnames, all other wireless networks in range of the router, memory statistics, and components of the configuration of the device such as enabled features. Affected devices: Affected devices are: Wavlink WN530HG4, Wavlink WN575A3, Wavlink WN579G3,Wavlink WN531G3, Wavlink WN533A8, Wavlink WN531A6, Wavlink WN551K1, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, WN572HG3, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000
Project Subscriptions
| Vendors | Products |
|---|---|
|
Wavlink
Subscribe
|
Jetstream Ac3000
Subscribe
Jetstream Ac3000 Firmware
Subscribe
Jetstream Erac3000
Subscribe
Jetstream Erac3000 Firmware
Subscribe
Wl-wn530hg4
Subscribe
Wl-wn530hg4 Firmware
Subscribe
Wl-wn575a3
Subscribe
Wl-wn575a3 Firmware
Subscribe
Wl-wn579g3
Subscribe
Wl-wn579g3 Firmware
Subscribe
Wn530h4
Subscribe
Wn530h4 Firmware
Subscribe
Wn531a6
Subscribe
Wn531a6 Firmware
Subscribe
Wn531g3
Subscribe
Wn531g3 Firmware
Subscribe
Wn533a8
Subscribe
Wn533a8 Firmware
Subscribe
Wn535g3
Subscribe
Wn535g3 Firmware
Subscribe
Wn551k1
Subscribe
Wn551k1 Firmware
Subscribe
Wn578a2
Subscribe
Wn578a2 Firmware
Subscribe
Wn579g3
Subscribe
Wn579g3 Firmware
Subscribe
Wn579x3
Subscribe
Wn579x3 Firmware
Subscribe
Wn57x93
Subscribe
Wn57x93 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4579 | An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can be accessed externally without any authentication. All the pages follow the naming convention live_(string).shtml. Among the information disclosed is: interface status logs, IP address of the device, MAC address of the device, model and current firmware version, location, all running processes, all interfaces and their statuses, all current DHCP leases and the associated hostnames, all other wireless networks in range of the router, memory statistics, and components of the configuration of the device such as enabled features. Affected devices: Affected devices are: Wavlink WN530HG4, Wavlink WN575A3, Wavlink WN579G3,Wavlink WN531G3, Wavlink WN533A8, Wavlink WN531A6, Wavlink WN551K1, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, WN572HG3, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:48:58.488Z
Reserved: 2020-04-26T00:00:00
Link: CVE-2020-12266
No data.
Status : Modified
Published: 2020-04-27T15:15:12.860
Modified: 2024-11-21T04:59:24.417
Link: CVE-2020-12266
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD