CVE-2020-12127
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 7.40% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- wavlink/wn530h4 firmware
- Source
- cve@mitre.org
References
- https://cerne.xyz/bugs/CVE-2020-12127Third Party Advisory
- https://www.wavlink.com/en_us/product/WL-WN530H4.htmlProduct, Vendor Advisory
- https://cerne.xyz/bugs/CVE-2020-12127Third Party Advisory
- https://www.wavlink.com/en_us/product/WL-WN530H4.htmlProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.