The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-21290 The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:41:00.245Z

Reserved: 2020-11-17T00:00:00

Link: CVE-2020-28899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-16T17:15:13.307

Modified: 2024-11-21T05:23:14.907

Link: CVE-2020-28899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.