CVE-2020-10972: High severity wavlink wl-wn530hg4 firmware vulnerability
An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live?.shtml page with the variable syspasswd). Affected Devices: Wavlink WN530HG4, Wavlink WN531G3, and Wavlink WN572HG3
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10972?
The severity of CVE-2020-10972 is high with a CVSS score of 7.5.
Which devices are affected by CVE-2020-10972?
The affected devices are Wavlink WN530HG4, Wavlink Wn531g3 Firmware, and Wavlink Wn572hg3 Firmware.
How can an attacker exploit CVE-2020-10972?
An attacker can exploit CVE-2020-10972 by accessing a page with the current administrator password in cleartext, without requiring authentication.
Is Wavlink WN530HG4 vulnerable to CVE-2020-10972?
Yes, Wavlink WN530HG4 is vulnerable to CVE-2020-10972.
How can I mitigate CVE-2020-10972?
To mitigate CVE-2020-10972, it is recommended to apply the latest firmware updates provided by Wavlink.