CVE-2020-12127
WAVLINK WN530H4 M30H4.V5030.190403 - Information Disclosure
Record summary
CVE-2020-12127 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHWAVLINK WN530H4 M30H4.V5030.190403 - Information DisclosureCVSS 7.5
WAVLINK WN530H4 M30H4.V5030.190403 contains an information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint. This can allow an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.
Impact
An attacker can exploit this vulnerability to gain access to sensitive information, such as router configuration settings and user credentials.
Remediation
Apply the latest firmware update provided by the vendor to fix the information disclosure vulnerability.
Source: ProjectDiscovery