Level1 EAP Devices offer a function do download the device config file. This download mechanism is not properly protected such that an attacker can download the config file without authentication. Passwords can be retrieved at this point.
feb798abe8963cbdf88203291b080caa2b0b13a15a35c236457fb84cc061ff8d