PT-2020-15637 · Pix Link · Pix-Link Repeater/Router Lv-Wr07
N0Hat
·
Published
2020-08-30
·
Updated
2020-08-31
·
CVE-2020-24104
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PIX-Link Repeater/Router LV-WR07 version v28K.Router.20170904
Description
The issue allows attackers to steal credentials without being connected to the network, using a crafted ESSID as the attack vector, specifically targeting the
SET2 parameter in the wireless.htm page.Recommendations
For PIX-Link Repeater/Router LV-WR07 version v28K.Router.20170904, avoid using the
SET2 parameter in the wireless.htm page until the issue is resolved. Consider changing the ESSID to a random value and restricting access to the wireless network to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pix-Link Repeater/Router Lv-Wr07