CVE-2020-10973
Description
An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated POST request to /cgi-bin/ExportAllSettings.sh on multiple Wavlink routers exposes admin password with trivial decryption.
Vulnerability
The vulnerability resides in the /cgi-bin/ExportAllSettings.sh endpoint on Wavlink WN530HG4, WN531G3, WN533A8, and WN551K1 devices. A crafted POST request without authentication returns the full device configuration, including the administrator password. The password is encrypted but all decryption information is readily available [1][2][3].
Exploitation
An attacker with network access to the device can send an unauthenticated POST request to /cgi-bin/ExportAllSettings.sh. The response contains the configuration file, which includes the encrypted admin password. The attacker can then decrypt the password using publicly known methods, as the decryption key and algorithm are easily obtainable [1][2].
Impact
Successful exploitation allows an attacker to obtain the administrator password, leading to full administrative control over the affected Wavlink router. This can result in complete compromise of the device, including modification of settings, interception of network traffic, and potential lateral movement within the network [1][2][3].
Mitigation
As of the publication date (2020-05-07), no official patch has been released by Wavlink. Users are advised to restrict network access to the device's web interface, disable remote management if not needed, and monitor for firmware updates. The affected devices may be end-of-life; consider replacing them with supported hardware [1][2][3].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Wavlink/WN530HG4description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10973mitrex_refsource_MISC
- github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10973-affected_devicesmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.