Medium severity6.5NVD Advisory· Published Jan 18, 2020· Updated Jun 17, 2026
CVE-2020-7227
CVE-2020-7227
Description
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, backup.asp, sys-power.asp, ifaces-wls.asp, ifaces-wls-pkt.asp, and ifaces-wls-pkt-adv.asp.
Affected products
4cpe:2.3:o:westermo:mrd-315_firmware:1.7.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:westermo:mrd-315_firmware:1.7.3:*:*:*:*:*:*:*
- cpe:2.3:o:westermo:mrd-315_firmware:1.7.4:*:*:*:*:*:*:*
- Westermo/MRD-315description
Patches
Vulnerability mechanics
References
1- sku11army.blogspot.com/2020/01/westermo-source-code-disclousure-in.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.