FNKvision FNK-GU2 wpa_supplicant.conf cleartext storage

CVE Details

Basic Information

Title FNKvision FNK-GU2 wpa_supplicant.conf cleartext storage
Type cve
Published 2025-07-09T04:02:05.353Z
Modified 2025-07-09T04:02:05.353Z

Product Information

Vendor FNKvision
Product FNK-GU2
Version 40.1.0

CVSS Information

Base Score 1.0 (LOW)
Attack Vector CVSS:4.0/AV:P/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description This vulnerability in FNKvision FNK-GU2 devices up to version 40.1.7 allows sensitive information to be stored in cleartext within the wpa_supplicant.conf file. This could expose data to unauthorized parties. The issue is considered low severity due to the specific conditions required for exploitation.
AI Severity Low
AI Vendor FNKvision
AI Product FNK-GU2
AI Version 40.1.0, 40.1.1, 40.1.2, 40.1.3, 40.1.4, 40.1.5, 40.1.6, 40.1.7

Affected Products

  • FNKvision FNK-GU2 40.1.0
  • FNKvision FNK-GU2 40.1.1
  • FNKvision FNK-GU2 40.1.2
  • FNKvision FNK-GU2 40.1.3
  • FNKvision FNK-GU2 40.1.4
  • FNKvision FNK-GU2 40.1.5
  • FNKvision FNK-GU2 40.1.6
  • FNKvision FNK-GU2 40.1.7

Additional Information

CWE List CWE-312, CWE-310
Source VulDB

Description

A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_supplicant.conf. The manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.