Vulnerability Description
Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), via the getpage parameter to /cgi-bin/webproc.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chinamobileltd | Gpn2.4P21-C-Cn Firmware | w2000en-01 |
| Chinamobileltd | Gpn2.4P21-C-Cn | 0.05 |
Related Weaknesses (CWE)
References
- https://github.com/cybertoxin/CVEs/blob/main/CVE_2020_18331.mdExploitThird Party Advisory
- https://medium.com/%40SergiuSechel/insecure-permissions-and-multiple-vulnerabili
- https://github.com/cybertoxin/CVEs/blob/main/CVE_2020_18331.mdExploitThird Party Advisory
- https://medium.com/%40SergiuSechel/insecure-permissions-and-multiple-vulnerabili
FAQ
What is CVE-2020-18331?
CVE-2020-18331 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), via the getpage parameter t...
How severe is CVE-2020-18331?
CVE-2020-18331 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-18331?
Check the references section above for vendor advisories and patch information. Affected products include: Chinamobileltd Gpn2.4P21-C-Cn Firmware, Chinamobileltd Gpn2.4P21-C-Cn.