CVE-2020-25206 Information
Description
The web console for Mimosa B5 B5c and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput WANStats PhyStats and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the affected endpoints (/core/api/calls/Throughput.php /core/api/calls/WANStats.php /core/api/calls/PhyStats.php /core/api/calls/QosStats.php). This results in the complete takeover of the vulnerable device. This vulnerability does not occur in the older 1.5.x firmware versions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://labs.f-secure.com/advisories/ https://labs.f-secure.com/advisories/mimosa-ptp-devices-multiple-vulnerabilities/
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: