peter bassill · operator
$ cve CVE-2020-25015 JSON

CVE-2020-25015 EXPLOIT

6.5
MEDIUM · CVSS 3.1 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS3.1% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2020-09-16
Last modified2026-06-17

Affected (2)

VendorProduct
genexisplatinum 4410
genexisplatinum 4410 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD