CVE-2020-21991 Details
Description
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.exploit-db.com/exploits/47822 | CVE | ExploitThird Party AdvisoryVDB Entry |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5549.php | CVE | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/47822 | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5549.php | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ave dominaplus | >= 1.10.11, <= 1.10.77 |
CPE
Remediation
| |
| ave 53ab-wbs firmware | 1.10.62 |
CPE
Remediation
| |
| ave 53ab-wbs | All versions |
CPE
Remediation
| |
| ave ts01 firmware | 1.0.65 |
CPE
Remediation
| |
| ave ts01 | All versions |
CPE
Remediation
| |
| ave ts03x-v firmware | 1.10.45a |
CPE
Remediation
| |
| ave ts03x-v | All versions |
CPE
Remediation
| |
| ave ts04x-v firmware | 1.10.45a |
CPE
Remediation
| |
| ave ts04x-v | All versions |
CPE
Remediation
| |
| ave ts05 firmware | 1.10.36 |
CPE
Remediation
| |
| ave ts05 | All versions |
CPE
Remediation
| |
| ave ts05n-v firmware | All versions |
CPE
Remediation
| |
| ave ts05n-v | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 19, 2021 | Initial Analysis | [email protected] |