← back
CVE-2025-29870highCWE-306

CVE-2025-29870

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 0.6%
exploitation probability
0.6%top 57% of all CVEs
observed exploitation
nono source reports it
In short

The Wi-Fi AC-WPS-11ac series access point allows anyone on the network to view sensitive configuration details, including login credentials, without needing to authenticate first. This is dangerous because attackers can use this information to take control of the device or access other systems.

Technical detail

A missing authentication control on a critical administrative function in the AC-WPS-11ac Wi-Fi AP enables unauthenticated remote attackers to retrieve configuration data via network access. The vulnerability exposes sensitive information including stored authentication credentials, requiring only network connectivity without prior authorization; impact includes unauthorized device takeover and lateral movement.

Summary generated and translated by AI from the official description.
Missing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attacker may obtain the product configuration information including authentication information.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N