VYPR

Apollo VX20

by WyreStorm

CVEs (3)

  • CVE-2024-25735CriMar 27, 2024
    risk 0.66cvss 9.1epss 0.51

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

  • CVE-2024-25736HigMar 27, 2024
    risk 0.52cvss 7.5epss 0.04

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.

  • CVE-2024-25734HigMar 27, 2024
    risk 0.52cvss 7.5epss 0.04

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.