漏洞描述
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext credentials for the SoftAP (access point) Router /device/config using an HTTP GET request.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
hyp3rlinx.altervista.orghttps://hyp3rlinx.altervista.org/advisories/WYRESTORM_APOLLO_VX20_INCORRECT_ACCESS_CONTROL_CREDENTIALS_DISCLOSURE_CVE-2024-25735.txt↗packetstormsecurity.comhttps://packetstormsecurity.com/files/cve/CVE-2024-25735↗packetstormsecurity.comhttp://packetstormsecurity.com/files/177082↗hyp3rlinx.altervista.orghttps://hyp3rlinx.altervista.org↗