Vulnerability Description
The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the affected endpoints (/core/api/calls/Throughput.php, /core/api/calls/WANStats.php, /core/api/calls/PhyStats.php, /core/api/calls/QosStats.php). This results in the complete takeover of the vulnerable device. This vulnerability does not occur in the older 1.5.x firmware versions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mimosa | B5 Firmware | >= 1.5.2, <= 2.8.0.3 |
| Mimosa | B5 | - |
| Mimosa | B5C Firmware | >= 1.5.2, < 2.8.1.0 |
| Mimosa | B5C | - |
| Mimosa | C5C Firmware | >= 1.5.2, < 2.8.1.0 |
| Mimosa | C5C | - |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/78.htmlThird Party Advisory
- https://labs.f-secure.com/advisories/Third Party Advisory
- https://labs.f-secure.com/advisories/mimosa-ptp-devices-multiple-vulnerabilitiesExploitThird Party Advisory
- https://cwe.mitre.org/data/definitions/78.htmlThird Party Advisory
- https://labs.f-secure.com/advisories/Third Party Advisory
- https://labs.f-secure.com/advisories/mimosa-ptp-devices-multiple-vulnerabilitiesExploitThird Party Advisory
FAQ
What is CVE-2020-25206?
CVE-2020-25206 is a vulnerability with a CVSS score of 7.2 (HIGH). The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to ...
How severe is CVE-2020-25206?
CVE-2020-25206 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25206?
Check the references section above for vendor advisories and patch information. Affected products include: Mimosa B5 Firmware, Mimosa B5, Mimosa B5C Firmware, Mimosa B5C, Mimosa C5C Firmware.