CVE-2020-8973

CRITICAL

ZGR TPS200 NG Firmware 2.00 - Unauthenticated Improper Access Control

Title source: llm
STIX 2.1

Description

ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacker with access to the network where the affected asset is located, to operate and change several parameters without having to be registered as a user on the web that owns the device.

Scores

CVSS v3 9.3
EPSS 0.0043
EPSS Percentile 34.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
zigor/zgr_tps200_ng_firmware 2.00
Published Oct 17, 2022
Tracked Since Feb 18, 2026