漏洞描述
Wavlink WN530HG4, WN531G3, WN533A8, and WN551K are susceptible to improper access control via /cgi-bin/ExportAllSettings.sh, where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10973↗github.comhttps://github.com/sudo-jtcsec/Nyra↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-10973↗github.comhttps://github.com/Roni-Carta/nyra↗github.comhttps://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10973-affected_devices↗