CVE-2024-25735

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP...

Basic Information

CVE State
PUBLISHED
Reserved Date
February 11, 2024
Published Date
March 27, 2024
Last Updated
October 28, 2024
Vendor
n/a
Product
n/a
Description
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

CVSS Scores

EPSS Score

Score
86.90% (Percentile: 99.37%) as of 2025-04-29

SSVC Information

Exploitation
poc
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2025-04-23 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-04-24 00:00:00 UTC

Scanner Integrations