vendor:
APOLLO VX20
by:
John Page (aka hyp3rlinx)
6.1
CVSS
HIGH
Incorrect Access Control (Credentials Disclosure)
287
CWE
Product Name: APOLLO VX20
Affected Version From: APOLLO VX20 < 1.3.58
Affected Version To: 21245
Patch Exists: YES
Related CWE: CVE-2024-25735
CPE: a:wyrestorm:apollo_vx20:1.3.57
Platforms Tested:
2024
WyreStorm Apollo VX20 Incorrect Access Control Credentials Disclosure
An issue in WyreStorm Apollo VX20 devices before version 1.3.58 allows remote attackers to access cleartext credentials for the SoftAP Router configuration using an HTTP GET request, leading to unauthorized disclosure of sensitive information.
Mitigation:
Update to version 1.3.58 or later to mitigate this vulnerability. Restrict network access to the affected components and implement proper access controls.