CVE-2020-21991
CRITICALAVE Dominaplus < 1.10.77 - Authentication Bypass
Title source: ruleDescription
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0528
EPSS Percentile
90.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (7)
ave/53ab-wbs_firmware
1.10.62
ave/dominaplus
1.10.11 - 1.10.77
ave/ts01_firmware
1.0.65
ave/ts03x-v_firmware
1.10.45a
ave/ts04x-v_firmware
1.10.45a
ave/ts05_firmware
1.10.36
ave/ts05n-v_firmware
Published
Apr 28, 2021
Tracked Since
Feb 18, 2026