Vulnerability Details CVE-2024-40091
Vilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated attackers to retrieve logs with sensitive system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.0%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2024-40091
-
cpe:2.3:h:viloliving:vilo_5:-
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.123
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.129
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.133
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.166
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.176
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.186
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.206
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.209
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.84
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.13
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.19
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.26
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.33
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.9
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.6.0.38