CVE-2021-44260 Scanner

Targets the /live_mfg.html endpoint without authentication, allowing remote attackers to retrieve MAC addresses, firmware versions, and other device configuration details.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

20 days 15 hours

Scan only one

URL

Toolbox

The WAVLINK AC1200 is a dual-band wireless router designed for home and small office environments, offering reliable internet connectivity and network management features. It is widely used due to its affordability and support for modern wireless standards like 802.11ac. The router provides a web-based interface for configuration, including firewall settings, parental controls, and guest network access. Small businesses often deploy this device to ensure stable network performance for daily operations. Regular firmware updates are essential to maintain security and functionality.

CVE-2021-44260 is an information disclosure vulnerability that arises from improper access controls on the router's web interface. Specifically, the /live_mfg.html page exposes sensitive manufacturing and configuration data without requiring authentication. This flaw occurs because the endpoint fails to verify user identity before serving data, allowing any remote attacker to retrieve internal details. The vulnerability is classified with a CVSS score of 7.5, indicating high severity due to the ease of exploitation and potential data exposure.

The vulnerable endpoint is /live_mfg.html, which is intended for manufacturing diagnostics but left accessible post-deployment. An attacker can send a simple HTTP GET request to this page to obtain data such as MAC addresses, firmware version, serial numbers, and other hardware identifiers. No special privileges or session tokens are needed, making it trivial to exploit. The information is returned in plain text or HTML format, enabling quick extraction by automated scripts or manual browsing.

If exploited, an attacker gains insight into the router's configuration and network topology, which can be used for further attacks like device fingerprinting or targeted exploits. Exposed MAC addresses may allow tracking of devices on the network, while firmware versions reveal potential unpatched vulnerabilities. This information leakage undermines network security and privacy, potentially leading to unauthorized access or data breaches. Immediate remediation is critical to prevent exploitation.

Get started to protecting your digital assets