CVE-2023-41027CWE-210
Juplink RX4-1500 Credential Disclosure Vulnerability
High · published September 22, 2023
What it is
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.
The record
Technical detail
- CVSS v3.1
- 8.0 · HIGH
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00761 · 52.9th percentile
- Weakness
- CWE-210 · Self-generated Error Message Containing Sensitive Information
- Published
- 2023-09-22T16:06Z
EPSS history
Timeline