peter bassill · operator
$ cve CVE-2020-14930 JSON

CVE-2020-14930 EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 3.4% (pctl 88)

Patch early

A public exploit exists.

Description

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.36% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-319
On CISA KEVno
Public exploityes
Published2020-06-19
Last modified2026-06-17

Affected (1)

VendorProduct
bt ctroms terminal projectbt ctroms terminal

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD