Authentication Bypass Vulnerability in Genexis Platinum-4410 Devices
CVE-2020-6170
9.8CRITICAL
What is CVE-2020-6170?
The Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices are susceptible to an authentication bypass vulnerability. This flaw allows attackers to gain unauthorized access to sensitive information, specifically user credentials, embedded within the HTML source code of the device's web interface at the cgi-bin/index2.asp URI. As a result, attackers can exploit this vulnerability to obtain cleartext credentials, posing a significant risk to device security and user privacy.