vendor:
                    APOLLO VX20
                by:
                    John Page (aka hyp3rlinx)
                6.1
                        CVSS
                    HIGH
                    Incorrect Access Control (Credentials Disclosure)
                    287
                        CWE
                    Product Name: APOLLO VX20
                    Affected Version From:  APOLLO VX20 < 1.3.58
                    Affected Version To:  1.3.1958
                    Patch Exists: YES
                    Related CWE: CVE-2024-25735
                    CPE:  a:wyrestorm:apollo_vx20:1.3.57
                    Platforms Tested:  
                    2024
                    WyreStorm APOLLO VX20 Incorrect Access Control Credentials Disclosure
A vulnerability exists in WyreStorm Apollo VX20 devices prior to version 1.3.58, allowing remote attackers to retrieve clear text credentials for the SoftAP Router's device configuration using an HTTP GET request. This can lead to unauthorized access to sensitive information. An attacker can exploit this issue by making an HTTP request to retrieve the credentials.
Mitigation:
					To mitigate this vulnerability, users should update the WyreStorm Apollo VX20 firmware to version 1.3.58 or later. Additionally, restrict network access to the device to trusted sources only.