Description
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.
Published: 2021-03-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-21290 The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.
History

No history.

Subscriptions

Zyxel Lte4506-m606 Lte4506-m606 Firmware Lte7460-m608 Lte7460-m608 Firmware Wah7706 Wah7706 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:41:00.245Z

Reserved: 2020-11-17T00:00:00.000Z

Link: CVE-2020-28899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-16T17:15:13.307

Modified: 2024-11-21T05:23:14.907

Link: CVE-2020-28899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses