CVE-2023-41027
22.09.2023, 17:15
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.Enginsight
Vendor | Product | Version |
---|---|---|
juplink | rx4-1500_firmware | 1.0.4 |
juplink | rx4-1500_firmware | 1.0.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-210 - Self-generated Error Message Containing Sensitive InformationThe software identifies an error condition and creates its own diagnostic or error messages that contain sensitive information.
- CWE-209 - Generation of Error Message Containing Sensitive InformationThe software generates an error message that includes sensitive information about its environment, users, or associated data.