CVE-2020-21991
28.04.2021, 14:15
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.Enginsight
Vendor | Product | Version |
---|---|---|
ave | dominaplus | 1.10.11 ≤ 𝑥 ≤ 1.10.77 |
ave | 53ab-wbs_firmware | 1.10.62 |
ave | ts01_firmware | 1.0.65 |
ave | ts03x-v_firmware | 1.10.45a:a |
ave | ts04x-v_firmware | 1.10.45a:a |
ave | ts05_firmware | 1.10.36 |
ave | ts05n-v_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration