CVE-2020-12127
CVE-2020-12127
Vexday Risk Score
18Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 6.4%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
02 Oct 2020Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →