CVE-2020-21991: Ave 53ab-Wbs Firmware

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.

Affected products

  • Ave 53ab-Wbs Firmware: version 1.10.62 only
  • Ave Dominaplus: from 1.10.11, up to and including 1.10.77
  • Ave TS01 Firmware: version 1.0.65 only
  • Ave TS03X-V Firmware: version 1.10.45a only
  • Ave TS04X-V Firmware: version 1.10.45a only
  • Ave TS05 Firmware: version 1.10.36 only
  • Ave TS05N-V Firmware: affected versions not specified

Published 2021-04-28. Last modified 2026-06-17.