CVE-2020-21994
9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.66% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-522 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-04-28 |
| Last modified | 2026-06-17 |
Affected (13)
| Vendor | Product |
|---|---|
| ave | 53ab-wbs |
| ave | 53ab-wbs firmware |
| ave | dominaplus |
| ave | ts01 |
| ave | ts01 firmware |
| ave | ts03x-v |
| ave | ts03x-v firmware |
| ave | ts04x-v |
| ave | ts04x-v firmware |
| ave | ts05 |
| ave | ts05 firmware |
| ave | ts05n-v |
| ave | ts05n-v firmware |
References
- https://cwe.mitre.org/data/definitions/522.html
- https://www.exploit-db.com/exploits/47819
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5550.php
- https://cwe.mitre.org/data/definitions/522.html
- https://www.exploit-db.com/exploits/47819
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5550.php
→ the Explorer · watch your stack · NVD