Clear Text Password Vulnerability in HTTP Protocol

Clear Text Password Vulnerability in HTTP Protocol

CVE-2021-23846 · MEDIUM Severity

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.

Learn more about our User Device Pen Test.