HIGH · 7.2

CVE-2020-25206

The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to ...

Vulnerability Description

The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the affected endpoints (/core/api/calls/Throughput.php, /core/api/calls/WANStats.php, /core/api/calls/PhyStats.php, /core/api/calls/QosStats.php). This results in the complete takeover of the vulnerable device. This vulnerability does not occur in the older 1.5.x firmware versions.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MimosaB5 Firmware>= 1.5.2, <= 2.8.0.3
MimosaB5-
MimosaB5C Firmware>= 1.5.2, < 2.8.1.0
MimosaB5C-
MimosaC5C Firmware>= 1.5.2, < 2.8.1.0
MimosaC5C-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-25206?

CVE-2020-25206 is a vulnerability with a CVSS score of 7.2 (HIGH). The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to ...

How severe is CVE-2020-25206?

CVE-2020-25206 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-25206?

Check the references section above for vendor advisories and patch information. Affected products include: Mimosa B5 Firmware, Mimosa B5, Mimosa B5C Firmware, Mimosa B5C, Mimosa C5C Firmware.