CVE-2020-37093

Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve WiFi passwords through the netcore_get.cgi endpoint. Attackers can send a GET request to the endpoint to extract sensitive network credentials including SSID and WiFi passwords in plain text.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Netis E1+ 1.2.32533 contiene una vulnerabilidad de revelación de información que permite a atacantes no autenticados recuperar contraseñas de WiFi a través del endpoint netcore_get.cgi. Los atacantes pueden enviar una solicitud GET al endpoint para extraer credenciales de red sensibles, incluyendo SSID y contraseñas de WiFi en texto plano.

03 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 22:16

Updated : 2026-06-17 03:16


NVD link : CVE-2020-37093

Mitre link : CVE-2020-37093

CVE.ORG link : CVE-2020-37093


JSON object : View

Products Affected

No product.

CWE
CWE-201

Insertion of Sensitive Information Into Sent Data