Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5pr-32h7-qgvw

Опубликовано: 08 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way.

WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 10%
0.00036
Низкий

8.7 High

CVSS4

Дефекты

CWE-256
CWE-306

Связанные уязвимости

nvd
9 месяцев назад

WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 10%
0.00036
Низкий

8.7 High

CVSS4

Дефекты

CWE-256
CWE-306