← Back

CVE-2020-21991

nvd nist
Published: Apr 28, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.

Affected (7)

7 products
Dominaplus
53ab Wbs Firmware
Ts01 Firmware
Ts03x V Firmware
Ts04x V Firmware
Ts05 Firmware
Ts05n V Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.10.11 to 1.10.77
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.10.62
Running on/withPlatform Versions
Ave
53ab Wbs
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.65
Running on/withPlatform Versions
Ave
Ts01
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.10.45a
Running on/withPlatform Versions
Ave
Ts03x V
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.10.45a
Running on/withPlatform Versions
Ave
Ts04x V
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.10.36
Running on/withPlatform Versions
Ave
Ts05
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Ave
Ts05n V
All versions

References (4)

Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.