PT-2021-11112 · Mimosa · Mimosa C5X+1

Published

2021-07-20

·

Updated

2022-10-05

·

CVE-2020-25206

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Mimosa B5, B5c, and C5x firmware versions through 2.8.0.2
Description: The web console for the affected firmware allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the affected endpoints, such as "/core/api/calls/Throughput.php", "/core/api/calls/WANStats.php", "/core/api/calls/PhyStats.php", and "/core/api/calls/QosStats.php". This results in the complete takeover of the vulnerable device.
Recommendations: For Mimosa B5, B5c, and C5x firmware versions through 2.8.0.2, consider disabling access to the affected API endpoints until a patch is available. Restrict access to the Throughput, WANStats, PhyStats, and QosStats API classes to minimize the risk of exploitation. Avoid using the web console account until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-25206

Affected Products

Mimosa B5C
Mimosa C5X