S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 18, 2024

CVE-2024-25735 Scanner

Detects 'Information Disclosure' vulnerability in WyreStorm Apollo VX20 affects v. before 1.3.58.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
apollo_vx20by wyrestorm
AFFECTED< 1.3.58SAFE ✓≥ 1.3.58
Updated Sep 18, 2026View on NVD →
Detail

Vulnerability Overview

The CVE-2024-25735 vulnerability exists in WyreStorm Apollo VX20 devices before version 1.3.58, allowing remote attackers to access cleartext credentials for the SoftAP Router via a simple HTTP GET request.

Vulnerability Details

This vulnerability stems from improper access control on the /device/config endpoint. Attackers can exploit this flaw to retrieve sensitive information, including cleartext credentials, directly affecting the confidentiality of the device's network settings.

Possible Effects

  • Confidentiality Breach: Exposure of critical network configurations and credentials.
  • Unauthorized Access: Potential for unauthorized access to the network, leading to further exploitations.

Why Choose S4E

S4E equips you with advanced vulnerability scanning solutions, including the CVE-2024-25735 Scanner, designed to detect and mitigate potential security flaws in your network infrastructure. Our platform offers:

  • Comprehensive vulnerability assessment tailored to your specific security needs.
  • Expert recommendations for effective remediation strategies.
  • Continuous support and insights from cybersecurity professionals to bolster your defenses against evolving threats.

Join S4E to empower your cybersecurity posture with state-of-the-art scanning technology and expert guidance.

References

Solution Advice
  • Firmware Update: Immediately update WyreStorm Apollo VX20 devices to firmware version 1.3.58 or later.
  • Access Control: Review and enforce strict access control policies for device configuration endpoints.
  • Network Monitoring: Enhance monitoring of network activity for unusual access patterns that may indicate exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-25735 scanner - Information Disclosure vulnerability in WyreStorm Apollo VX20 | S4E