CVE-2020-12106: Stengg Vpncrypt m10 Firmware

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point.

Affected products

  • Stengg Vpncrypt m10 Firmware: version 2.6.5 only

Published 2020-08-12. Last modified 2026-06-17.