high·Misconfiguration·Updated Nov 26, 2024

CVE-2021-44260 Scanner

Targets the /live_mfg.html endpoint without authentication, allowing remote attackers to retrieve MAC addresses, firmware versions, and other device configuration details.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-44260
7.5
CVSS

A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of router.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The WAVLINK AC1200 is a dual-band wireless router designed for home and small office environments, offering reliable internet connectivity and network management features. It is widely used due to its affordability and support for modern wireless standards like 802.11ac. The router provides a web-based interface for configuration, including firewall settings, parental controls, and guest network access. Small businesses often deploy this device to ensure stable network performance for daily operations. Regular firmware updates are essential to maintain security and functionality.

CVE-2021-44260 is an information disclosure vulnerability that arises from improper access controls on the router's web interface. Specifically, the /live_mfg.html page exposes sensitive manufacturing and configuration data without requiring authentication. This flaw occurs because the endpoint fails to verify user identity before serving data, allowing any remote attacker to retrieve internal details. The vulnerability is classified with a CVSS score of 7.5, indicating high severity due to the ease of exploitation and potential data exposure.

The vulnerable endpoint is /live_mfg.html, which is intended for manufacturing diagnostics but left accessible post-deployment. An attacker can send a simple HTTP GET request to this page to obtain data such as MAC addresses, firmware version, serial numbers, and other hardware identifiers. No special privileges or session tokens are needed, making it trivial to exploit. The information is returned in plain text or HTML format, enabling quick extraction by automated scripts or manual browsing.

If exploited, an attacker gains insight into the router's configuration and network topology, which can be used for further attacks like device fingerprinting or targeted exploits. Exposed MAC addresses may allow tracking of devices on the network, while firmware versions reveal potential unpatched vulnerabilities. This information leakage undermines network security and privacy, potentially leading to unauthorized access or data breaches. Immediate remediation is critical to prevent exploitation.

Solution Advice
  • Update the WAVLINK AC1200 firmware to the latest version provided by the manufacturer to patch CVE-2021-44260.
  • Restrict access to the router's web interface by enabling IP whitelisting or VPN access only.
  • Disable the /live_mfg.html endpoint if not required, or block it via firewall rules.
  • Implement strong authentication mechanisms for all administrative pages to prevent unauthorized access.
  • Regularly monitor network logs for unusual requests to sensitive endpoints like /live_mfg.html.
  • Apply security best practices such as changing default credentials and disabling remote management.
  • Conduct periodic vulnerability scans using tools like S4E to identify and address similar issues.
  • Educate users about the risks of exposing router interfaces to the internet and enforce network segmentation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.