Vulnerability record · CVE-2020-10974 · published 7 May 2020
CVE-2020-10974: Wavlink wl-wn575a3 firmware missing authentication for critical function vulnerability
Wavlink · Wl Wn575a3 Firmware
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000
Description
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Roni-Carta/nyra | Not ApplicableThird Party Advisory |
| https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10974 | Third Party Advisory |
| https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10974-affected_devices | Third Party Advisory |
| https://github.com/sudo-jtcsec/Nyra | Broken Link |
| https://github.com/Roni-Carta/nyra | Not ApplicableThird Party Advisory |
| https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10974 | Third Party Advisory |
| https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10974-affected_devices | Third Party Advisory |
| https://github.com/sudo-jtcsec/Nyra | Broken Link |
Track CVE-2020-10974 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10974), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.