CVE-2024-25735

CRITICAL EXPLOITED NUCLEI

WyreStorm Apollo VX20 - Information Disclosure

Title source: nuclei

Description

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

Exploits (1)

exploitdb WORKING POC
by hyp3rlinx · textremotemultiple
https://www.exploit-db.com/exploits/51816

Nuclei Templates (1)

WyreStorm Apollo VX20 - Information Disclosure
HIGHVERIFIEDby johnk3r
Shodan: ssl:"WyreStorm Apollo VX20" || ssl:"wyrestorm apollo vx20"

Scores

CVSS v3 9.1
EPSS 0.9078
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

VulnCheck KEV 2024-03-03
CWE
CWE-319
Status published
Products (1)
wyrestorm/apollo_vx20_firmware < 1.3.58
Published Mar 27, 2024
Tracked Since Feb 18, 2026