HIGH · 8.8

CVE-2020-24365

An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on th...

Vulnerability Description

An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed as the root user (uid 0). (Even if a login is required, most routers are left with default credentials.)

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GemteksWrtm-127Acn Firmware01.01.02.141
GemteksWrtm-127Acn-
GemteksWrtm-127X9 Firmware01.01.02.127
GemteksWrtm-127X9-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-24365?

CVE-2020-24365 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on th...

How severe is CVE-2020-24365?

CVE-2020-24365 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-24365?

Check the references section above for vendor advisories and patch information. Affected products include: Gemteks Wrtm-127Acn Firmware, Gemteks Wrtm-127Acn, Gemteks Wrtm-127X9 Firmware, Gemteks Wrtm-127X9.