Versio.io

CVE-2020-24365

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 24-09-2020 05:15
Last modified: - 28-04-2022 08:21
Total changes: - 3

Description

An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed as the root user (uid 0). (Even if a login is required, most routers are left with default credentials.)

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
High
Confidentiality
High
Integrity
Low
Privileges required
Unchanged
Scope
None
User interaction
8.8
Base score
2.8
5.9
Exploitability score
Impact score
 

Verification logic

OR
AND
OR
vendor=gemteks AND product=wrtm-127acn_firmware AND version=01.01.02.141
OR
vendor=gemteks AND product=wrtm-127acn AND version=-
AND
OR
vendor=gemteks AND product=wrtm-127x9_firmware AND version=01.01.02.127
OR
vendor=gemteks AND product=wrtm-127x9 AND version=-
 

Reference

 


Keywords

NVD

 

CVE-2020-24365

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.