CVE-2020-37093

HIGH

Netis E1+ 1.2.32533 - Info Disclosure

Title source: llm

Description

Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve WiFi passwords through the netcore_get.cgi endpoint. Attackers can send a GET request to the endpoint to extract sensitive network credentials including SSID and WiFi passwords in plain text.

Exploits (1)

exploitdb WORKING POC
by Besim · textwebappshardware
https://www.exploit-db.com/exploits/48384

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 17.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-201
Status draft

Timeline

Published Feb 03, 2026
Tracked Since Feb 18, 2026