vendor:
APOLLO VX20
by:
John Page (aka hyp3rlinx)
6.1
CVSS
HIGH
Incorrect Access Control (Credentials Disclosure)
287
CWE
Product Name: APOLLO VX20
Affected Version From: APOLLO VX20 < 1.3.58
Affected Version To: 1.3.1958
Patch Exists: YES
Related CWE: CVE-2024-25735
CPE: a:wyrestorm:apollo_vx20:1.3.57
Platforms Tested:
2024
WyreStorm APOLLO VX20 Incorrect Access Control Credentials Disclosure
A vulnerability exists in WyreStorm Apollo VX20 devices prior to version 1.3.58, allowing remote attackers to retrieve clear text credentials for the SoftAP Router's device configuration using an HTTP GET request. This can lead to unauthorized access to sensitive information. An attacker can exploit this issue by making an HTTP request to retrieve the credentials.
Mitigation:
To mitigate this vulnerability, users should update the WyreStorm Apollo VX20 firmware to version 1.3.58 or later. Additionally, restrict network access to the device to trusted sources only.