PT-2020-1429 · Genexis · Genexis Platinum 4410 V2+1

Published

2020-01-08

·

Updated

2022-01-01

·

CVE-2020-6170

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Genexis Platinum-P4410-V2 versions 1.28 and earlier Genexis Platinum-4410 versions 2.1 and earlier
Description The issue is related to insufficient authentication in the cgi-bin/index2.asp component of the Genexis Platinum-P4410-V2 and Genexis Platinum-4410 router software. This allows a remote attacker to obtain authentication credentials for access to the router's administration panel by viewing the HTML source code of the login page. The vulnerable API endpoint is "cgi-bin/index2.asp".
Recommendations For Genexis Platinum-P4410-V2 version 1.28, update to a version that fixes the authentication bypass issue. For Genexis Platinum-4410 version 2.1, update to a version that fixes the authentication bypass issue. As a temporary workaround, consider restricting access to the cgi-bin/index2.asp endpoint until a patch is available.

Exploit

Fix

Improper Authentication

Missing Authentication

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00403
CVE-2020-6170

Affected Products

Genexis Platinum-4410
Genexis Platinum 4410 V2