CVE-2020-10974 - CVE House
Back to Database
Status published High CVE-2020-10974

An issue was discovered affecting a backup feature where a...

Vulnerability Description

An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-10974

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

wl-wn575a3 firmware, wl-wn579g3 firmware, wn531a6 firmware, wn535g3 firmware, wn530h4 firmware, wn57x93 firmware, wn572hg3 firmware, wn575a4 firmware, wn578a2 firmware, wn579g3 firmware, wn579x3 firmware, jetstream ac3000 firmware, jetstream erac3000 firmware
Vulnerable Versions:
rpt75a3.v4300.180801, m79x3.v5030.180719

Timeline

Official Publish: May 7th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.