vendor:
Netis E1+
by:
Besim ALTINOK
7.5
CVSS
HIGH
Unauthenticated WiFi Password Leak
200
CWE
Product Name: Netis E1+
Affected Version From: 1.2.32533
Affected Version To: 1.2.32533
Patch Exists: YES
Related CWE: N/A
CPE: h:netis_systems:netis_e1+
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Netis E1+ V1.2.32533
2020
Netis E1+ 1.2.32533 – Unauthenticated WiFi Password Leak
A vulnerability in Netis E1+ 1.2.32533 allows an unauthenticated attacker to leak the WiFi password by sending a specially crafted HTTP request to the netcore_get.cgi file. This vulnerability can be exploited remotely.
Mitigation:
Upgrade to the latest version of Netis E1+ 1.2.32533 or later.