CVE-2020-12106
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- stengg/vpncrypt m10 firmware
- Source
- cve@mitre.org
References
- https://www.stengg.com/cybersecurityThird Party Advisory
- https://www.stengg.com/media/1076253/vpncrypt-m10-cve-advisory-notice.pdfThird Party Advisory
- https://www.stengg.com/cybersecurityThird Party Advisory
- https://www.stengg.com/media/1076253/vpncrypt-m10-cve-advisory-notice.pdfThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.