CVE-2020-10974

An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wavlink:wl-wn575a3_firmware:rpt75a3.v4300.180801:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wl-wn575a3:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:wavlink:wl-wn579g3_firmware:m79x3.v5030.180719:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wl-wn579g3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:wavlink:wn531a6_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn531a6:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:wavlink:wn535g3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn535g3:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:wavlink:wn530h4_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn530h4:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:wavlink:wn57x93_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn57x93:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:wavlink:wn572hg3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn572hg3:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:wavlink:wn575a4_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn575a4:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:wavlink:wn578a2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn578a2:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:wavlink:wn579g3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn579g3:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:wavlink:wn579x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wn579x3:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:wavlink:jetstream_ac3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:jetstream_ac3000:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:wavlink:jetstream_erac3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:jetstream_erac3000:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:56

Type Values Removed Values Added
References () https://github.com/Roni-Carta/nyra - Not Applicable, Third Party Advisory () https://github.com/Roni-Carta/nyra - Not Applicable, Third Party Advisory
References () https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10974 - Third Party Advisory () https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10974 - Third Party Advisory
References () https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10974-affected_devices - Third Party Advisory () https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10974-affected_devices - Third Party Advisory
References () https://github.com/sudo-jtcsec/Nyra - Broken Link () https://github.com/sudo-jtcsec/Nyra - Broken Link

Information

Published : 2020-05-07 18:15

Updated : 2024-11-21 04:56


NVD link : CVE-2020-10974

Mitre link : CVE-2020-10974

CVE.ORG link : CVE-2020-10974


JSON object : View

Products Affected

wavlink

  • wn535g3_firmware
  • wn575a4_firmware
  • wl-wn575a3
  • jetstream_erac3000_firmware
  • wl-wn575a3_firmware
  • wn579g3_firmware
  • wn572hg3
  • wn579x3
  • wn530h4
  • wn530h4_firmware
  • wn531a6_firmware
  • wl-wn579g3_firmware
  • jetstream_erac3000
  • wn535g3
  • wn579g3
  • jetstream_ac3000
  • wn57x93
  • wn531a6
  • jetstream_ac3000_firmware
  • wn572hg3_firmware
  • wl-wn579g3
  • wn57x93_firmware
  • wn578a2_firmware
  • wn579x3_firmware
  • wn578a2
  • wn575a4
CWE
CWE-306

Missing Authentication for Critical Function