VYPR
Unrated severityNVD Advisory· Published Oct 2, 2020· Updated Aug 4, 2024

CVE-2020-12127

CVE-2020-12127

Description

An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The WAVLINK WN530H4 router exposes cleartext login details and other sensitive settings via an unauthenticated endpoint.

Vulnerability

An information disclosure vulnerability exists in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 router running firmware version M30H4.V5030.190403 [1]. The endpoint does not require any authentication, allowing an attacker to retrieve the full router configuration, including cleartext login credentials, DNS settings, and other sensitive data [1].

Exploitation

An attacker can exploit this vulnerability by sending a direct HTTP request to the vulnerable endpoint (/cgi-bin/ExportAllSettings.sh) from any network-adjacent or remote position, without needing prior authentication, user interaction, or any special privileges [1]. No write access or race condition is required – the endpoint responds immediately with the settings file.

Impact

Successful exploitation leads to full disclosure of the router's settings, including cleartext login credentials (such as the administrator username and password), DNS server entries, and other configuration details [1]. This information can be used by an attacker to gain administrative access to the router, potentially enabling further attacks on the internal network or modification of router settings.

Mitigation

As of the publication date (2020-10-02), no patch or updated firmware has been released by WAVLINK to address this vulnerability [1]. Users are advised to restrict network access to the management interface, place the router behind a firewall, or consider replacing the device if no fix is provided. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the knowledge cutoff.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • WAVLINK/WN530H4description
  • Range: = M30H4.V5030.190403 firmware

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.