CVE-2023-31196
No sign of exploitation. No public exploitation artifact known so far.
These Wi-Fi access points are missing authentication checks on certain functions, allowing anyone on the network to access sensitive information without logging in. This is a serious problem because attackers can steal configuration data and other private details.
Missing authentication mechanism (CWE-306) in critical functions of affected Wi-Fi AP units enables unauthenticated remote attackers to retrieve sensitive information. The vulnerability requires network access to the device but no credentials, allowing disclosure of configuration and operational data. Impacts all listed AC-PD-WAPU, AC-PD-WAPUM, AC-WAPU-300, and AC-WAPUM-300 series up to specified firmware versions.