CVE-2020-21991 - CVE House
Back to Database
Status published Critical CVE-2020-21991

AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due...

Vulnerability Description

AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-21991

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

dominaplus, 53ab-wbs firmware, ts01 firmware, ts03x-v firmware, ts04x-v firmware, ts05 firmware, ts05n-v firmware
Vulnerable Versions:
1.10.11, 1.10.62, 1.0.65, 1.10.45a, 1.10.36

Timeline

Official Publish: April 28th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.