Vulnerabilities > Wavlink > Wn572Hg3 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-05-07 CVE-2020-10974 Missing Authentication for Critical Function vulnerability in Wavlink products
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password.
network
low complexity
wavlink CWE-306
5.0
2020-05-07 CVE-2020-10972 Insufficiently Protected Credentials vulnerability in Wavlink products
An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page.
network
low complexity
wavlink CWE-522
5.0