CVE-2020-24365

HIGH

Gemtek WRTM-127ACN/WRTM-127x9 - Command Injection

Title source: llm

Description

An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed as the root user (uid 0). (Even if a login is required, most routers are left with default credentials.)

Exploits (1)

exploitdb WORKING POC
by Gabriele Zuddas · pythonwebappscgi
https://www.exploit-db.com/exploits/49079

Scores

CVSS v3 8.8
EPSS 0.1415
EPSS Percentile 94.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-1188
Status published
Products (2)
gemteks/wrtm-127acn_firmware 01.01.02.141
gemteks/wrtm-127x9_firmware 01.01.02.127
Published Sep 24, 2020
Tracked Since Feb 18, 2026