CVE-2020-10973: High severity wavlink wl-wn530hg4 firmware vulnerability
An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10973?
CVE-2020-10973 is a vulnerability affecting Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 devices, allowing an attacker to retrieve the device's configuration, including the administrator password, without authentication.
How severe is CVE-2020-10973?
CVE-2020-10973 has a severity score of 7.5, which is classified as high.
Which devices are affected by CVE-2020-10973?
Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 devices are affected by CVE-2020-10973.
Is authentication required to exploit CVE-2020-10973?
No authentication is required to exploit CVE-2020-10973.
How can I fix CVE-2020-10973?
Currently, there is no known fix for CVE-2020-10973. It is recommended to contact the vendor or apply any patches or updates they provide.