CVE-2024-42657

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nepstech:ntpl-xpon1gfevn_firmware:1.0:*:*:*:*:*:*:*
cpe:2.3:h:nepstech:ntpl-xpon1gfevn:-:*:*:*:*:*:*:*

History

20 Aug 2024, 16:13

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-311
CWE-200
Summary
  • (es) Un problema en el enrutador Wifi Wishnet Nepstech NTPL-XPON1GFEVN v1.0 permite a un atacante remoto obtener información confidencial a través de la falta de cifrado durante el proceso de inicio de sesión.
References () https://github.com/sudo-subho/CVE-2024-42657 - () https://github.com/sudo-subho/CVE-2024-42657 - Third Party Advisory
References () https://www.linkedin.com/in/subhodeep-baroi-397629252/ - () https://www.linkedin.com/in/subhodeep-baroi-397629252/ - Third Party Advisory
References () https://x.com/sudo_subho - () https://x.com/sudo_subho - Permissions Required
First Time Nepstech
Nepstech ntpl-xpon1gfevn
Nepstech ntpl-xpon1gfevn Firmware
CPE cpe:2.3:h:nepstech:ntpl-xpon1gfevn:-:*:*:*:*:*:*:*
cpe:2.3:o:nepstech:ntpl-xpon1gfevn_firmware:1.0:*:*:*:*:*:*:*

19 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-19 17:15

Updated : 2024-08-20 16:13


NVD link : CVE-2024-42657

Mitre link : CVE-2024-42657

CVE.ORG link : CVE-2024-42657


JSON object : View

Products Affected

nepstech

  • ntpl-xpon1gfevn_firmware
  • ntpl-xpon1gfevn
CWE
CWE-311

Missing Encryption of Sensitive Data

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor