CVE-2020-25015 EXPLOIT
6.5
MEDIUM · CVSS 3.1 · EPSS 3.1% (pctl 87)
Patch early
A public exploit exists.
Description
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password.
Scoring
| CVSS | 6.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
| EPSS | 3.1% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-09-16 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| genexis | platinum 4410 |
| genexis | platinum 4410 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF | 2020-11-09 |
References
- http://packetstormsecurity.com/files/159936/Genexis-Platinum-4410-P4410-V2-1.28-Missing-Access-Control-CSRF.html
- https://www.getastra.com/blog/911/csrf-broken-access-control-in-genexis-platinum-4410/
- https://www.jinsonvarghese.com/broken-access-control-csrf-in-genexis-platinum-4410/
- http://packetstormsecurity.com/files/159936/Genexis-Platinum-4410-P4410-V2-1.28-Missing-Access-Control-CSRF.html
- https://www.getastra.com/blog/911/csrf-broken-access-control-in-genexis-platinum-4410/
- https://www.jinsonvarghese.com/broken-access-control-csrf-in-genexis-platinum-4410/
→ the Explorer · watch your stack · NVD