CVE-2020-9420

MEDIUM

Arcadyan VRV9506JAC23 Firmware - Cleartext Transmission of Sensitive Information via Web Administrative Dashboard Login

Title source: llm
STIX 2.1

Description

The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allowing an attacker to sniff and intercept traffic to learn the administrative credentials to the router.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0047
EPSS Percentile 36.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (1)
arcadyan/vrv9506jac23_firmware
Published Dec 14, 2022
Tracked Since Feb 18, 2026