Vulnerabilities > Wavlink > Wn530H4 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-10-02 CVE-2020-12127 Information Exposure vulnerability in Wavlink Wn530H4 Firmware M30H4.V5030.190403
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.
network
low complexity
wavlink CWE-200
5.0
2020-05-07 CVE-2020-10974 Missing Authentication for Critical Function vulnerability in Wavlink products
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password.
network
low complexity
wavlink CWE-306
5.0
2020-04-27 CVE-2020-12266 Missing Authentication for Critical Function vulnerability in Wavlink products
An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage.
network
low complexity
wavlink CWE-306
5.0