Vulnerability Description
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ave | Dominaplus | >= 1.10.11, <= 1.10.77 |
| Ave | 53Ab-Wbs Firmware | 1.10.62 |
| Ave | 53Ab-Wbs | - |
| Ave | Ts01 Firmware | 1.0.65 |
| Ave | Ts01 | - |
| Ave | Ts03X-V Firmware | 1.10.45a |
| Ave | Ts03X-V | - |
| Ave | Ts04X-V Firmware | 1.10.45a |
| Ave | Ts04X-V | - |
| Ave | Ts05 Firmware | 1.10.36 |
| Ave | Ts05 | - |
| Ave | Ts05N-V Firmware | - |
| Ave | Ts05N-V | - |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/47822ExploitThird Party AdvisoryVDB Entry
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5549.phpExploitThird Party Advisory
- https://www.exploit-db.com/exploits/47822ExploitThird Party AdvisoryVDB Entry
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5549.phpExploitThird Party Advisory
FAQ
What is CVE-2020-21991?
CVE-2020-21991 is a vulnerability with a CVSS score of 9.8 (CRITICAL). AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autol...
How severe is CVE-2020-21991?
CVE-2020-21991 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-21991?
Check the references section above for vendor advisories and patch information. Affected products include: Ave Dominaplus, Ave 53Ab-Wbs Firmware, Ave 53Ab-Wbs, Ave Ts01 Firmware, Ave Ts01.