CVE-2020-10972
Last modified
CVE-2020-10972 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live_?.shtml page with the variable syspasswd). EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live_?.shtml page with the variable syspasswd). Affected Devices: Wavlink WN530HG4, Wavlink WN531G3, and Wavlink WN572HG3
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wavlink | Wn530hg4 Firmware | m30hg4.v5030.191116 |
| Wavlink | Wn531g3 Firmware | All versions |
| Wavlink | Wn572hg3 Firmware | All versions |
References
- https://github.com/Roni-Carta/nyraNot Applicable, Third Party Advisory
- https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10972Third Party Advisory
- https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10972-affected_devicesThird Party Advisory
- https://github.com/sudo-jtcsec/NyraBroken Link
- https://github.com/Roni-Carta/nyraNot Applicable, Third Party Advisory
- https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10972Third Party Advisory
- https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10972-affected_devicesThird Party Advisory
- https://github.com/sudo-jtcsec/NyraBroken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10972?
How severe is CVE-2020-10972?
How do I fix CVE-2020-10972?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10966In the Password Reset Module in VESTA Control Panel through …6.5
- CVE-2020-10967In Dovecot before 2.3.10.1, remote unauthenticated attackers…5.3
- CVE-2020-10968FasterXML jackson-databind 2.x before 2.9.10.4 mishandles th…8.8
- CVE-2020-10969FasterXML jackson-databind 2.x before 2.9.10.4 mishandles th…8.8
- CVE-2020-1097<p>An information disclosure vulnerability exists when the W…6.5
- CVE-2020-10971An issue was discovered on Wavlink Jetstream devices where a…8.8
- CVE-2020-10973An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3…7.5
- CVE-2020-10974An issue was discovered affecting a backup feature where a c…7.5
- CVE-2020-10975GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments o…4.3
- CVE-2020-10976GitLab EE/CE 8.17 to 12.9 is vulnerable to information leaka…7.5
- CVE-2020-10977GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversa…5.5
- CVE-2020-10978GitLab EE/CE 8.11 to 12.9 is leaking information on Issues o…5.3
Are you affected by CVE-2020-10972?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
