CVE-2020-10974
Published on: 05/07/2020 12:00:00 AM UTC
Last Modified on: 04/28/2022 07:30:00 PM UTC
Certain versions of Jetstream Ac3000 from Wavlink contain the following vulnerability:
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000
- CVE-2020-10974 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
GitHub - Roni-Carta/nyra | github.com text/html |
![]() |
CVE/CVE-2020-10974 at master · sudo-jtcsec/CVE · GitHub | Third Party Advisory github.com text/html |
![]() |
GitHub - sudo-jtcsec/Nyra: If you have a Wavlink router, its Not Your Router Anymore | github.com text/html |
![]() |
CVE/CVE-2020-10974-affected_devices at master · sudo-jtcsec/CVE · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Wavlink | Jetstream Ac3000 | - | All | All | All |
Operating System | Wavlink | Jetstream Ac3000 Firmware | - | All | All | All |
Hardware
| Wavlink | Jetstream Erac3000 | - | All | All | All |
Operating System | Wavlink | Jetstream Erac3000 Firmware | - | All | All | All |
Hardware
| Wavlink | Wl-wn575a3 | - | All | All | All |
Hardware
| Wavlink | Wl-wn575a3 | - | All | All | All |
Operating System | Wavlink | Wl-wn575a3 Firmware | rpt75a3.v4300.180801 | All | All | All |
Operating System | Wavlink | Wl-wn575a3 Firmware | rpt75a3.v4300.180801 | All | All | All |
Hardware
| Wavlink | Wl-wn579g3 | - | All | All | All |
Hardware
| Wavlink | Wl-wn579g3 | - | All | All | All |
Operating System | Wavlink | Wl-wn579g3 Firmware | m79x3.v5030.180719 | All | All | All |
Operating System | Wavlink | Wl-wn579g3 Firmware | m79x3.v5030.180719 | All | All | All |
Hardware
| Wavlink | Wn530h4 | - | All | All | All |
Operating System | Wavlink | Wn530h4 Firmware | - | All | All | All |
Hardware
| Wavlink | Wn531a6 | - | All | All | All |
Operating System | Wavlink | Wn531a6 Firmware | - | All | All | All |
Hardware
| Wavlink | Wn535g3 | - | All | All | All |
Operating System | Wavlink | Wn535g3 Firmware | - | All | All | All |
Hardware
| Wavlink | Wn572hg3 | - | All | All | All |
Operating System | Wavlink | Wn572hg3 Firmware | - | All | All | All |
Hardware
| Wavlink | Wn575a4 | - | All | All | All |
Operating System | Wavlink | Wn575a4 Firmware | - | All | All | All |
Hardware
| Wavlink | Wn578a2 | - | All | All | All |
Operating System | Wavlink | Wn578a2 Firmware | - | All | All | All |
Hardware
| Wavlink | Wn579g3 | - | All | All | All |
Operating System | Wavlink | Wn579g3 Firmware | - | All | All | All |
Hardware
| Wavlink | Wn579x3 | - | All | All | All |
Operating System | Wavlink | Wn579x3 Firmware | - | All | All | All |
Hardware
| Wavlink | Wn57x93 | - | All | All | All |
Operating System | Wavlink | Wn57x93 Firmware | - | All | All | All |
- cpe:2.3:h:wavlink:jetstream_ac3000:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:jetstream_ac3000_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:jetstream_erac3000:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:jetstream_erac3000_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wl-wn575a3:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wl-wn575a3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wl-wn575a3_firmware:rpt75a3.v4300.180801:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wl-wn575a3_firmware:rpt75a3.v4300.180801:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wl-wn579g3:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wl-wn579g3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wl-wn579g3_firmware:m79x3.v5030.180719:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wl-wn579g3_firmware:m79x3.v5030.180719:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wn530h4:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wn530h4_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wn531a6:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wn531a6_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wn535g3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wn535g3_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wn572hg3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wn572hg3_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wn575a4:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wn575a4_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wn578a2:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wn578a2_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wn579g3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wn579g3_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wn579x3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wn579x3_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:wavlink:wn57x93:-:*:*:*:*:*:*:*:
- cpe:2.3:o:wavlink:wn57x93_firmware:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|