CVE-2020-21991: Ave 53ab-Wbs Firmware
Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.
Affected products
- Ave 53ab-Wbs Firmware: version 1.10.62 only
- Ave Dominaplus: from 1.10.11, up to and including 1.10.77
- Ave TS01 Firmware: version 1.0.65 only
- Ave TS03X-V Firmware: version 1.10.45a only
- Ave TS04X-V Firmware: version 1.10.45a only
- Ave TS05 Firmware: version 1.10.36 only
- Ave TS05N-V Firmware: affected versions not specified
Published 2021-04-28. Last modified 2026-06-17.