CVE Vulnerabilities

CVE-2024-25735

Cleartext Transmission of Sensitive Information

Published: Mar 27, 2024 | Modified: May 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Apollo_vx20_firmware Wyrestorm * 1.3.58 (excluding)

Potential Mitigations

References