CVE-2023-41027CWE-210

Juplink RX4-1500 Credential Disclosure Vulnerability

High · published September 22, 2023

CVSS v3.1
8.0
EPSS
1%
Percentile
52.9
In the wild
Unconfirmed
What it is

Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.

The record
Technical detail
CVSS v3.1
8.0 · HIGH
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00761 · 52.9th percentile
Weakness
CWE-210 · Self-generated Error Message Containing Sensitive Information
Published
2023-09-22T16:06Z
EPSS history
Timeline
  • 22 SEP 16:06Z
    Juplink RX4-1500 Credential Disclosure Vulnerability
    cvelistv5