The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module’s Operating System.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12107
Reference (s):
- https://www.stengg.com/cybersecurity
- https://www.stengg.com/media/1076253/vpncrypt-m10-cve-advisory-notice.pdf

