CVE-2020-10918
Description
This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authentication mechanism. The issue is due to insufficient authentication on post-authentication requests. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from unauthenticated users. Was ZDI-CAN-10182.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
C-MORE HMI EA9 firmware 6.52 lacks authentication checks on post-authentication requests, allowing remote attackers to bypass authentication entirely.
Vulnerability
C-MORE HMI EA9 touch screen panels running firmware version 6.52 contain an authentication bypass vulnerability. The specific flaw exists within the authentication mechanism; the device fails to properly authenticate requests that should require authentication, effectively treating them as if they are post-authentication requests [1]. This allows any remote attacker to access resources that are normally protected.
Exploitation
An attacker does not need any authentication or prior access; the vulnerability is exploitable remotely with network access to the affected device [1]. No user interaction or special privileges are required. By sending crafted requests to the HMI, an attacker can bypass the authentication checks and interact with the device's protected interfaces.
Impact
Successful exploitation allows an attacker to escalate privileges and access resources normally protected from unauthenticated users. This can lead to unauthorized information disclosure, as the CVSS vector indicates high confidentiality impact. The attacker gains the ability to read sensitive data or perform actions reserved for authenticated operators without proper authorization [1].
Mitigation
C-MORE released firmware version 6.6 to fix this issue; the fix is included in that version and later releases [1]. Users should update their HMI EA9 panels to version 6.6 or newer. No workarounds are documented. The vulnerability was disclosed via the Zero Day Initiative (ZDI-20-805) [1]. It is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- C-MORE/HMI EA9v5Range: Firmware version 6.52
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.zerodayinitiative.com/advisories/ZDI-20-805/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.