VYPR

LS9 LS1.5/p7040

by Libre Wireless

CVEs (3)

  • CVE-2020-35758CriMay 3, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to internal functionality. Despite presenting a password login page on first access, authentication is not…

  • CVE-2020-35756HigMay 3, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_service daemon running on port 7777 does not require authentication to return the device configuration password in cleartext when…

  • CVE-2020-35755HigMay 3, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_service deamon running on port 7777 provides a sub-category of commands for which Read_ is prepended. Commands in this category are…