CVE-2020-18330
Description
An issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), allows attackers to gain access to the configuration interface.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN ships with no admin password on port 8080 and has a directory traversal vulnerability, exposing configuration and sensitive files.
Vulnerability
The ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running firmware version W2000EN-01 (hardware platform Gpn2.4P21-C_WIFI-V0.05) is shipped and deployed without an administrative password on port 8080. The web configuration interface is accessible at http://:8080. Additionally, a directory traversal vulnerability exists in the /cgi-bin/webproc endpoint, allowing retrieval of arbitrary files such as /etc/shadow via a crafted getpage parameter [1].
Exploitation
An attacker with network access to the router's port 8080 can exploit the blank password to directly access the configuration interface. Alternatively, the directory traversal can be triggered by sending a GET request to /cgi-bin/webproc?getpage=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fshadow&errorpage=html/main.html&var:language=zh_cn&var:menu=setup&var:page=connected&var:retag=1&var:subpage=- [1]. No authentication is required for either attack vector.
Impact
Successful exploitation allows an attacker to change router configuration, potentially gaining access to the internal network. The directory traversal reveals the /etc/shadow file, exposing hashed passwords for the root and #tw user accounts [1]. This can lead to full compromise of the device and lateral movement within the network.
Mitigation
Adding a password to the admin user accounts reduces the risk of exploitation via the blank password. However, the directory traversal vulnerability remains, and the #tw account password cannot be changed by the user [1]. No official firmware patch has been released as of the publication date. Over 4,300 devices were identified as vulnerable via Shodan, primarily in South America and Asia [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- ChinaMobile/PLC Wireless Router model GPN2.4P21-C-CNdescription
- Range: W2000EN-01 (hardware platform Gpn2.4P21-C_WIFI-V0.05)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.