PT-2024-4077 · Wyrestorm · Wyrestorm Apollo Vx20

Hyp3Rlinx

·

Published

2024-02-18

·

Updated

2024-10-28

·

CVE-2024-25735

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WyreStorm Apollo VX20 versions prior to 1.3.58
Description An issue allows remote attackers to discover cleartext passwords via a SoftAP "GET /device/config" request. This is due to a lack of encrypted confidential data.
Recommendations For versions prior to 1.3.58, update to version 1.3.58 or later to resolve the issue. As a temporary workaround, consider restricting access to the SoftAP /device/config endpoint until a patch is available.

Exploit

Fix

Missing Encryption of Sensitive Data

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-04525
CVE-2024-25735

Affected Products

Wyrestorm Apollo Vx20