PT-2020-12458 · Wavlink · Wavlink Wn551K1+4

Published

2020-05-07

·

Updated

2022-04-28

·

CVE-2020-10973

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Wavlink WN530HG4 Wavlink WN531G3 Wavlink WN533A8 Wavlink WN551K1 Wavlink WL-WN530HG4 version M30HG4.V5030.191116
Description An issue was discovered affecting the /cgi-bin/ExportAllSettings.sh endpoint, where a crafted POST request can return the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.
Recommendations For Wavlink WN530HG4, consider disabling access to the /cgi-bin/ExportAllSettings.sh endpoint until a patch is available. For Wavlink WN531G3, restrict access to the /cgi-bin/ExportAllSettings.sh endpoint to minimize the risk of exploitation. For Wavlink WN533A8, avoid using the /cgi-bin/ExportAllSettings.sh endpoint until the issue is resolved. For Wavlink WN551K1, consider implementing additional authentication measures for the /cgi-bin/ExportAllSettings.sh endpoint as a temporary workaround. For Wavlink WL-WN530HG4 version M30HG4.V5030.191116, restrict access to the /cgi-bin/ExportALLSettings.sh endpoint to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10973

Affected Products

Wavlink Wl-Wn530Hg4
Wavlink Wn530H4
Wavlink Wn531P3
Wavlink Wn533A8
Wavlink Wn551K1