PT-2020-15709 · Gemtek · Gemtek Wrtm-127X9+1
Published
2020-09-24
·
Updated
2022-04-28
·
CVE-2020-24365
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Gemtek WRTM-127ACN version 01.01.02.141
Gemtek WRTM-127x9 version 01.01.02.127
Description
An issue allows an authenticated attacker to execute a command directly on the target machine via the Monitor Diagnostic network page. Commands are executed as the root user. This is particularly concerning since most routers are left with default credentials, potentially allowing attackers to gain access without needing to crack passwords.
Recommendations
For Gemtek WRTM-127ACN version 01.01.02.141, consider restricting access to the Monitor Diagnostic network page until a fix is available.
For Gemtek WRTM-127x9 version 01.01.02.127, consider restricting access to the Monitor Diagnostic network page until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gemtek Wrtm-127Acn
Gemtek Wrtm-127X9