CVE-2020-29669 is a critical vulnerability affecting the Macally WIFISD2-2A82 Media and Travel Router (firmware 2.000.010). This flaw allows a guest user to exploit a password reset process to gain administrative control, leading to shell access. The vulnerability has a CVSS score of 8.8 (High), indicating a network-exploitable, low-complexity attack that can result in complete compromise, including the ability to dump and crack password hashes for all users, including root. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and there is no evidence of active exploitation, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.000.010CPE matchmatch criteria | cpe:2.3:o:macally:wifisd2-2a82_firmware:2.000.010:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.