CVE-2020-10974: High severity wavlink wl-wn575a3 vulnerability
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10974?
CVE-2020-10974 is a vulnerability that allows an attacker to retrieve the administrator password of certain Wavlink devices through a crafted POST request.
Which devices are affected by CVE-2020-10974?
The affected devices include Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, and more.
Is authentication required to exploit CVE-2020-10974?
No, authentication is not required to exploit CVE-2020-10974.
What is the severity of CVE-2020-10974?
The severity of CVE-2020-10974 is high, with a CVSS score of 7.5.
How can I fix CVE-2020-10974?
There is no official fix available, but you can mitigate the vulnerability by applying security patches or firmware updates provided by Wavlink.