STAR Labs disclosed two vulnerabilities in the Askey AP5100W Wi-Fi mesh node that can let attackers on the local network gain administrative access and retrieve sensitive configuration data. In CVE-2020-25546, the web management interface was found to use a flawed authentication design that appears to set a global authenticated state after any successful login, rather than creating a user-specific session. Because the interface reportedly uses no session keys or cookies, a second user on the network may be able to access administrative functions once a legitimate administrator has logged in.
In CVE-2020-25545, the same device was reported to expose configuration backups containing sensitive data, including the admin password and Wi-Fi password. An authenticated attacker can generate and download the backup archive, and STAR Labs said that if a backup file already exists, it may be possible to retrieve it without authentication in a worst-case scenario. The researchers tested the issues on firmware Dual_SIG_1.01.071 and said the product had been supplied to Singtel broadband customers, while repeated disclosure attempts to Askey, CSA, Singtel, and MITRE reportedly received limited or no vendor response.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On publication of the advisories, STAR Labs publicly disclosed CVE-2020-25545, an information leak via insecure backups, and CVE-2020-25546, a logic flaw allowing web admin authentication bypass on the Askey AP5100W. The disclosures included technical details and noted the lack of vendor response.
According to the disclosure timelines in the advisories, STAR Labs made repeated attempts during 2020 to report the AP5100W vulnerabilities to Askey, Singapore's CSA, Singtel, and MITRE. The vendor reportedly did not respond, while other parties provided limited or delayed responses.
STAR Labs found that Askey AP5100W Wi-Fi mesh nodes running firmware version Dual_SIG_1.01.071 were affected by two issues: an authentication bypass caused by broken session handling and an insecure backup mechanism that exposed sensitive configuration data. The affected devices had been supplied to Singtel broadband customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.