Record summary

CVE-2020-12127 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWAVLINK WN530H4 M30H4.V5030.190403 - Information DisclosureCVSS 7.5

WAVLINK WN530H4 M30H4.V5030.190403 contains an information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint. This can allow an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.

Impact

An attacker can exploit this vulnerability to gain access to sensitive information, such as router configuration settings and user credentials.

Remediation

Apply the latest firmware update provided by the vendor to fix the information disclosure vulnerability.

WeaknessesCWE-306
Authorsarafatansari
Template tagscvecve2020wavlinkexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:wavlink:wn530h4_firmware:m30h4.v5030.190403:*:*:*:*:*:*:*
Shodan: http.html:"Wavlink"
Shodan: http.html:"wavlink"
FOFA: body="wavlink"

Source: ProjectDiscovery

References

3