Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The CLI sends upstream controller settings, including a sensitive token, to the device using plain HTTP via the /upstream/pull_settings endpoint. On a local network this can be intercepted or modified by any attacker with network position, exposing credentials and enabling tampering with the device's upstream configuration.
