PT-2021-11112 · Mimosa · Mimosa C5X+1
Published
2021-07-20
·
Updated
2022-10-05
·
CVE-2020-25206
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Mimosa B5, B5c, and C5x firmware versions through 2.8.0.2
Description:
The web console for the affected firmware allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the affected endpoints, such as "/core/api/calls/Throughput.php", "/core/api/calls/WANStats.php", "/core/api/calls/PhyStats.php", and "/core/api/calls/QosStats.php". This results in the complete takeover of the vulnerable device.
Recommendations:
For Mimosa B5, B5c, and C5x firmware versions through 2.8.0.2, consider disabling access to the affected API endpoints until a patch is available. Restrict access to the Throughput, WANStats, PhyStats, and QosStats API classes to minimize the risk of exploitation. Avoid using the web console account until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mimosa B5C
Mimosa C5X