HIGH🇬🇧 English

CVE-2020-12266

CVSS 7.5v3.1pub. 2020-04-27upd. 2024-11-21

An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can be accessed externally without any authentication. All the pages follow the naming convention live_(string).shtml. Among the information disclosed is: interface status logs, IP address of the device, MAC address of the device, model and current firmware version, location, all running processes, all interfaces and their statuses, all current DHCP leases and the associated hostnames, all other wireless networks in range of the router, memory statistics, and components of the configuration of the device such as enabled features. Affected devices: Affected devices are: Wavlink WN530HG4, Wavlink WN575A3, Wavlink WN579G3,Wavlink WN531G3, Wavlink WN533A8, Wavlink WN531A6, Wavlink WN551K1, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, WN572HG3, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Wavlink Jetstream Ac3000

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Jetstream Ac3000 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Jetstream Erac3000

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Jetstream Erac3000 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wl Wn530hg4

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wl Wn530hg4 Firmware

    OS
    Wavlink
    m30hg4.v5030.191116
  • Wavlink Wl Wn575a3

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wl Wn575a3 Firmware

    OS
    Wavlink
    rpt75a3.v4300.180801
  • Wavlink Wl Wn579g3

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wl Wn579g3 Firmware

    OS
    Wavlink
    m79x3.v5030.180719
  • Wavlink Wn530h4

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn530h4 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wn531a6

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn531a6 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wn531g3

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn531g3 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wn533a8

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn533a8 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wn535g3

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn535g3 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wn551k1

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn551k1 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wn578a2

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn578a2 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wn579g3

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn579g3 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wn579x3

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn579x3 Firmware

    OS
    Wavlink
    wszystkie wersje
  • Wavlink Wn57x93

    HW
    Wavlink
    wszystkie wersje
  • Wavlink Wn57x93 Firmware

    OS
    Wavlink
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-38861CRITICAL9.8PL ✓ten sam produkt

RCE w routerze Wavlink WL-WN575A3 poprzez parametr username w adm.cgi

CVE-2022-37149CRITICAL9.8PL ✓ten sam produkt

Command injection w routerze WAVLINK WL-WN575A3 przez parametr username

CVE-2022-35519CRITICAL9.8PL ✓ten sam produkt

Command injection w WAVLINK routerach przez parametr add_mac w firewall.cgi

CVE-2022-35518CRITICAL9.8PL ✓ten sam produkt

Command injection w WAVLINK nas.cgi — brak filtrowania parametrów User1Passwd i User1

CVE-2022-35520CRITICAL9.8PL ✓ten sam produkt

Command injection w routerach WAVLINK poprzez ukryty parametr ufconf