CVE-2024-25735: Wyrestorm Apollo VX20 Firmware

Critical severity, CVSS 9.1. EPSS: 50.6% chance of exploitation in the next 30 days.

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

Affected products

  • Wyrestorm Apollo VX20 Firmware: before 1.3.58 (fixed in 1.3.58)

Published 2024-03-27. Last modified 2026-06-17.