CVE-2020-12106
Summary
| CVE | CVE-2020-12106 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-12 19:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Stengg | Vpncrypt M10 | - | All | All | All |
| Hardware | Stengg | Vpncrypt M10 | - | All | All | All |
| Operating System | Stengg | Vpncrypt M10 Firmware | 2.6.5 | All | All | All |
| Operating System | Stengg | Vpncrypt M10 Firmware | 2.6.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cybersecurity - Digital Tech | ST Engineering | MISC | www.stengg.com | Third Party Advisory |
| www.stengg.com/media/1076253/vpncrypt-m10-cve-advisory-notice.pdf | MISC | www.stengg.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.