Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10974

Опубликовано: 07 мая 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:wavlink:wl-wn575a3_firmware:rpt75a3.v4300.180801:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wl-wn575a3:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:wavlink:wl-wn579g3_firmware:m79x3.v5030.180719:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wl-wn579g3:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:wavlink:wn531a6_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn531a6:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:wavlink:wn535g3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn535g3:-:*:*:*:*:*:*:*
Конфигурация 5

Одновременно

cpe:2.3:o:wavlink:wn530h4_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn530h4:-:*:*:*:*:*:*:*
Конфигурация 6

Одновременно

cpe:2.3:o:wavlink:wn57x93_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn57x93:-:*:*:*:*:*:*:*
Конфигурация 7

Одновременно

cpe:2.3:o:wavlink:wn572hg3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn572hg3:-:*:*:*:*:*:*:*
Конфигурация 8

Одновременно

cpe:2.3:o:wavlink:wn575a4_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn575a4:-:*:*:*:*:*:*:*
Конфигурация 9

Одновременно

cpe:2.3:o:wavlink:wn578a2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn578a2:-:*:*:*:*:*:*:*
Конфигурация 10

Одновременно

cpe:2.3:o:wavlink:wn579g3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn579g3:-:*:*:*:*:*:*:*
Конфигурация 11

Одновременно

cpe:2.3:o:wavlink:wn579x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn579x3:-:*:*:*:*:*:*:*
Конфигурация 12

Одновременно

cpe:2.3:o:wavlink:jetstream_ac3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:jetstream_ac3000:-:*:*:*:*:*:*:*
Конфигурация 13

Одновременно

cpe:2.3:o:wavlink:jetstream_erac3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:jetstream_erac3000:-:*:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.0034
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered on Wavlink WL-WN579G3 - M79X3.V5030.180719 and WL-WN575A3 - RPT75A3.V4300.180801 devices, affecting a backup feature. A crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required.

EPSS

Процентиль: 56%
0.0034
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-306