Information disclosure in P-660HN-T1 - CVE-2019-6725
Published: June 4, 2019
P-660HN-T1
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to output of administrator´s password in the HTML source code when accessing "rpWLANRedirect.asp" URL. A remote non authenticated attacker can view administrator´s password and gain unauthorized access to the device.
Example:
http://[host]/rpWLANRedirect.asp