CVE-2020-25206 is an authenticated command injection vulnerability affecting the web console of Mimosa B5, B5c, and C5x devices running firmware through version 2.8.0.2, excluding 1.5.x. Rated High severity (CVSS 7.2), it allows an attacker with web console credentials to execute operating system commands via crafted POST requests to specific API endpoints, leading to complete device compromise. Although not present in common public exploit databases, exploit code is confirmed to exist on GitHub and via VulnCheck KEV, indicating a high potential for exploitation. This vulnerability is listed on the Hot List and shows elevated community discussion, underscoring its relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.5.2, <= 2.8.0.3CPE matchmatch criteria | cpe:2.3:o:mimosa:b5_firmware:*:*:*:*:*:*:*:* | ||
>= 1.5.2, < 2.8.1.0CPE matchmatch criteria | cpe:2.3:o:mimosa:b5c_firmware:*:*:*:*:*:*:*:* | ||
>= 1.5.2, < 2.8.1.0CPE matchmatch criteria | cpe:2.3:o:mimosa:c5c_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.