CVE-2020-21994: Ave 53ab-Wbs Firmware

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.

Affected products

  • Ave 53ab-Wbs Firmware: version 1.10.62 only
  • Ave Dominaplus: from 1.10.11, up to and including 1.10.77
  • Ave TS01 Firmware: version 1.0.65 only
  • Ave TS03X-V Firmware: version 1.10.45a only
  • Ave TS04X-V Firmware: version 1.10.45a only
  • Ave TS05 Firmware: version 1.10.36 only
  • Ave TS05N-V Firmware: affected versions not specified

Published 2021-04-28. Last modified 2026-06-17.