CVE-2020-10972

HIGH

Wavlink WN530HG4, WN531G3, and WN572HG3 Firmware - Unauthenticated Administrator Password Exposure via live_?.shtml Page

Title source: llm
STIX 2.1

Description

An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live_?.shtml page with the variable syspasswd). Affected Devices: Wavlink WN530HG4, Wavlink WN531G3, and Wavlink WN572HG3

References (4)

Core 4

Scores

CVSS v3 7.5
EPSS 0.0173
EPSS Percentile 74.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-306 CWE-522
Status published
Products (3)
wavlink/wn530hg4_firmware m30hg4.v5030.191116
wavlink/wn531g3_firmware
wavlink/wn572hg3_firmware
Published May 07, 2020
Tracked Since Feb 18, 2026