CVE-2022-4985 - CVE House
Back to Database
Status published High CVE-2022-4985

Vodafone H500s WiFi Password Disclosure via activation.json

Vulnerability Description

Vodafone H500s devices running firmware v3.5.10 (hardware model Sercomm VFH500) expose the WiFi access point password via an unauthenticated HTTP endpoint. By sending a crafted GET request to /data/activation.json with specific headers and cookies, a remote attacker can retrieve a JSON document that contains the wifi_password field. This allows an unauthenticated attacker to obtain the WiFi credentials and gain unauthorized access to the wireless network, compromising confidentiality of network traffic and attached systems.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-4985

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Daniel Monzón (stark0de)

Affected Vendor

Affected Software

Vodafone H500s
Vulnerable Versions:
0

Timeline

Official Publish: November 14th, 2025
Last Modified: April 7th, 2026
Added to House: July 21st, 2026

CVSS Vectors

Weaknesses (CWE)