漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Vodafone H500s WiFi Password Disclosure via activation.json
Vulnerability Description
Vodafone H500s devices running firmware v3.5.10 (hardware model Sercomm VFH500) expose the WiFi access point password via an unauthenticated HTTP endpoint. By sending a crafted GET request to /data/activation.json with specific headers and cookies, a remote attacker can retrieve a JSON document that contains the wifi_password field. This allows an unauthenticated attacker to obtain the WiFi credentials and gain unauthorized access to the wireless network, compromising confidentiality of network traffic and attached systems.
CVSS Information
N/A
Vulnerability Type
将系统数据暴露到未授权控制的范围
Vulnerability Title
Vodafone H500s 安全漏洞
Vulnerability Description
Vodafone H500s是英国Vodafone公司的一款WiFi路由器。 Vodafone H500s v3.5.10版本存在安全漏洞,该漏洞源于未认证HTTP端点暴露WiFi密码,可能导致无线网络未授权访问。
CVSS Information
N/A
Vulnerability Type
N/A