CVE-2020-25011: Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Firmware
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to get username and password by request /cgi-bin/webadminget.cgi script via the browser.
Affected products
- Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Firmware: version r0002.p05 only
Published 2020-12-17. Last modified 2026-06-17.