VYPR
Unrated severityNVD Advisory· Published Jan 25, 2023· Updated Apr 1, 2025

CVE-2020-18330

CVE-2020-18330

Description

An issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), allows attackers to gain access to the configuration interface.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ChinaMobile PLC Wireless Router GPN2.4P21-C-CN ships with no admin password on port 8080 and has a directory traversal vulnerability, exposing configuration and sensitive files.

Vulnerability

The ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running firmware version W2000EN-01 (hardware platform Gpn2.4P21-C_WIFI-V0.05) is shipped and deployed without an administrative password on port 8080. The web configuration interface is accessible at http://:8080. Additionally, a directory traversal vulnerability exists in the /cgi-bin/webproc endpoint, allowing retrieval of arbitrary files such as /etc/shadow via a crafted getpage parameter [1].

Exploitation

An attacker with network access to the router's port 8080 can exploit the blank password to directly access the configuration interface. Alternatively, the directory traversal can be triggered by sending a GET request to /cgi-bin/webproc?getpage=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fshadow&errorpage=html/main.html&var:language=zh_cn&var:menu=setup&var:page=connected&var:retag=1&var:subpage=- [1]. No authentication is required for either attack vector.

Impact

Successful exploitation allows an attacker to change router configuration, potentially gaining access to the internal network. The directory traversal reveals the /etc/shadow file, exposing hashed passwords for the root and #tw user accounts [1]. This can lead to full compromise of the device and lateral movement within the network.

Mitigation

Adding a password to the admin user accounts reduces the risk of exploitation via the blank password. However, the directory traversal vulnerability remains, and the #tw account password cannot be changed by the user [1]. No official firmware patch has been released as of the publication date. Over 4,300 devices were identified as vulnerable via Shodan, primarily in South America and Asia [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • ChinaMobile/PLC Wireless Router model GPN2.4P21-C-CNdescription
  • Range: W2000EN-01 (hardware platform Gpn2.4P21-C_WIFI-V0.05)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.