Vulnerability Description
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed as the root user (uid 0). (Even if a login is required, most routers are left with default credentials.)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gemteks | Wrtm-127Acn Firmware | 01.01.02.141 |
| Gemteks | Wrtm-127Acn | - |
| Gemteks | Wrtm-127X9 Firmware | 01.01.02.127 |
| Gemteks | Wrtm-127X9 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/160136/Gemtek-WVRTM-127ACN-01.01.02.141-ComExploitThird Party AdvisoryVDB Entry
- https://pastebin.com/QTev1TjMExploitThird Party Advisory
- http://packetstormsecurity.com/files/160136/Gemtek-WVRTM-127ACN-01.01.02.141-ComExploitThird Party AdvisoryVDB Entry
- https://pastebin.com/QTev1TjMExploitThird Party Advisory
FAQ
What is CVE-2020-24365?
CVE-2020-24365 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on th...
How severe is CVE-2020-24365?
CVE-2020-24365 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24365?
Check the references section above for vendor advisories and patch information. Affected products include: Gemteks Wrtm-127Acn Firmware, Gemteks Wrtm-127Acn, Gemteks Wrtm-127X9 Firmware, Gemteks Wrtm-127X9.