CVE-2020-12127
- EPSS 18.47%
- Veröffentlicht 02.10.2020 09:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:18
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive informati...
CVE-2020-12126
- EPSS 0.65%
- Veröffentlicht 02.10.2020 09:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:18
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.
- EPSS 5.94%
- Veröffentlicht 02.10.2020 09:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:17
A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary machine instructions as root without authentication.
- EPSS 91.8%
- Veröffentlicht 02.10.2020 09:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:17
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.
CVE-2020-12123
- EPSS 0.14%
- Veröffentlicht 02.10.2020 09:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:17
CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, because these endpoints do not contain CSRF tokens. If a user is authenticated in the router portal, then...
CVE-2020-10974
- EPSS 0.34%
- Veröffentlicht 07.05.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:29
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavl...
CVE-2020-12266
- EPSS 0.42%
- Veröffentlicht 27.04.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:24
An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other s...