CVE-2020-11542: 3xlogic Infinias EIDC32 Firmware

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.

Affected products

  • 3xlogic Infinias EIDC32 Firmware: version 2.213 only
  • 3xlogic Infinias EIDC32 Web: version 1.107 only

Published 2020-04-04. Last modified 2026-06-17.