Back
CVE-2020-6170
CRITICAL
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.
Published: Jan 8, 2020
Modified: Jun 17, 2026
CWE-200
CWE-306
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| genexis | platinum-4410_firmware | 1.28 |
GitHub Security Advisory GHSA-m632-wxmw-j6qx
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows...
References (4)
- http://packetstormsecurity.com/files/156075/Genexis-Platinum-4410-2.1-Authentication-Bypass.html Exploit, Third Party Advisory, VDB Entry
- https://medium.com/%40husinulzsanub/exploiting-router-authentication-through-web-interface-68660c708206
- http://packetstormsecurity.com/files/156075/Genexis-Platinum-4410-2.1-Authentication-Bypass.html Exploit, Third Party Advisory, VDB Entry
- https://medium.com/%40husinulzsanub/exploiting-router-authentication-through-web-interface-68660c708206
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
7.33%
Top 6% most likely to be exploited
Threat Score
41.4 / 100
Data Sources
NVD
EPSS
GitHub