Librewireless operates in the wireless access-point and infrastructure space, with its disclosed vulnerabilities concentrating in the LS9 product line and its associated firmware. The recurring signal centers on missing authentication controls for critical administrative functions, a structural weakness in edge-facing network devices that can expose management interfaces to unauthorized access.
The number and severity of CVEs published that impact products developed by Librewireless over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35758CRITICAL An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to intern | May 3, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-35757CRITICAL An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides functionality to access ADB ove | May 3, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-35756HIGH An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_service daemon running on port | May 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-35755HIGH An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_service deamon running on port 7777 | May 3, 2021 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Librewireless.
Media articles that mention a CVE ID that affects a product developed by Librewireless — matched by CVE ID, not by vendor name.