Record summary

CVE-2020-10973 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWAVLINK - Access ControlCVSS 7.5

Wavlink WN530HG4, WN531G3, WN533A8, and WN551K are susceptible to improper access control via /cgi-bin/ExportAllSettings.sh, where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information or control of the affected device.

Remediation

Apply the latest firmware update provided by the vendor to fix the access control issue.

WeaknessesCWE-306
Authorsarafatansari
Template tagscvecve2020exposurewavlinkvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:wavlink:wn530hg4_firmware:m30hg4.v5030.191116:*:*:*:*:*:*:*
Shodan: http.html:"Wavlink"
Shodan: http.html:"wavlink"
FOFA: body="wavlink"

Source: ProjectDiscovery

References

5