.. / CVE-2020-12127

Exploit for WAVLINK WN530H4 M30H4.V5030.190403 - Information Disclosure (CVE-2020-12127)

Description:

WAVLINK WN530H4 M30H4.V5030.190403 contains an information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint. This can allow an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.

Nuclei Template

View the template here CVE-2020-12127.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-12127.yaml
Copy

References:

https://www.wavlink.com/en_us/product/WL-WN530H4.html
https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2020-12127
https://cerne.xyz/bugs/CVE-2020-12127
https://github.com/ARPSyndicate/kenzer-templates