HIGH

CVE-2020-25206

CVSS v3

7.2

HIGH

EPSS Score

19.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the affected endpoints (/core/api/calls/Throughput.php, /core/api/calls/WANStats.php, /core/api/calls/PhyStats.php, /core/api/calls/QosStats.php). This results in the complete takeover of the vulnerable device. This vulnerability does not occur in the older 1.5.x firmware versions.

Technical details

Published
7/20/2021

Frequently asked questions

What is CVE-2020-25206?

The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the affected endpoints (/core/api/calls/Throughput.php, /core/api/calls/WANStats.php, /core/api/calls/PhyStats.php, /core/api/calls/QosStats.php). This results in the complete takeover of the vulnerable device. This vulnerability does not occur in the older 1.5.x firmware versions.

Is CVE-2020-25206 actively exploited?

Active exploitation of CVE-2020-25206 has not been confirmed. The EPSS score is 19.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-25206?

CVE-2020-25206 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2020-25206 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.