PT-2024-4077 · Wyrestorm · Wyrestorm Apollo Vx20
Hyp3Rlinx
·
Published
2024-02-18
·
Updated
2024-10-28
·
CVE-2024-25735
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WyreStorm Apollo VX20 versions prior to 1.3.58
Description
An issue allows remote attackers to discover cleartext passwords via a SoftAP "GET /device/config" request. This is due to a lack of encrypted confidential data.
Recommendations
For versions prior to 1.3.58, update to version 1.3.58 or later to resolve the issue. As a temporary workaround, consider restricting access to the SoftAP /device/config endpoint until a patch is available.
Exploit
Fix
Missing Encryption of Sensitive Data
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wyrestorm Apollo Vx20