CVE-2020-25206observed exploitation

CVE-2020-25206

Published · Updated

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 5.3%
from disclosure to weapon
Published on NVDJul 20
VulnCheck+1245d
exploitation probability
5.3%top 8% of all CVEs
observed exploitation
yesVulnCheck
The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the affected endpoints (/core/api/calls/Throughput.php, /core/api/calls/WANStats.php, /core/api/calls/PhyStats.php, /core/api/calls/QosStats.php). This results in the complete takeover of the vulnerable device. This vulnerability does not occur in the older 1.5.x firmware versions.
Affected products
n/a · n/a