CVE-2020-10972 describes a critical vulnerability in Wavlink WN530HG4, WN531G3, and WN572HG3 routers, where an unauthenticated web page exposes the administrator password in cleartext. This allows an attacker to easily gain full administrative control over affected devices. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, leading to a complete compromise of confidentiality. While there is no evidence of active exploitation, public exploit code, or significant community discussion, the cleartext password exposure presents a severe risk to unpatched devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
m30hg4.v5030.191116CPE matchmatch criteria | cpe:2.3:o:wavlink:wn530hg4_firmware:m30hg4.v5030.191116:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:wavlink:wn531g3_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:wavlink:wn572hg3_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.