VulnerabilityModified
CVE-2020-25015
A specific router allows changing the Wi-Fi password remotely.
MEDIUM 6.5EPSS 3.10%
Does this matter?
Lower severity and a low EPSS score (3.10%). Track it; it rarely justifies an emergency change on its own.
Description
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 3.10% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- genexis/platinum 4410 firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/159936/Genexis-Platinum-4410-P4410-V2-1.28-Missing-Access-Control-CSRF.htmlExploit, Third Party Advisory, VDB Entry
- https://www.getastra.com/blog/911/csrf-broken-access-control-in-genexis-platinum-4410/Exploit, Third Party Advisory
- https://www.jinsonvarghese.com/broken-access-control-csrf-in-genexis-platinum-4410/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/159936/Genexis-Platinum-4410-P4410-V2-1.28-Missing-Access-Control-CSRF.htmlExploit, Third Party Advisory, VDB Entry
- https://www.getastra.com/blog/911/csrf-broken-access-control-in-genexis-platinum-4410/Exploit, Third Party Advisory
- https://www.jinsonvarghese.com/broken-access-control-csrf-in-genexis-platinum-4410/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.