CVE-2020-12127: High severity wavlink wl-wn530h4 firmware vulnerability
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12127?
CVE-2020-12127 is an information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 router firmware.
What is the severity of CVE-2020-12127?
CVE-2020-12127 has a severity rating of 7.5 (high).
How does CVE-2020-12127 work?
CVE-2020-12127 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information, without authentication.
Which software is affected by CVE-2020-12127?
The Wavlink WN530H4 M30H4.V5030.190403 firmware is affected by CVE-2020-12127.
How can I fix CVE-2020-12127?
To fix CVE-2020-12127, it is recommended to update the router firmware to a version that addresses the vulnerability.