VYPR
Unrated severityNVD Advisory· Published Feb 16, 2021· Updated May 30, 2025

CVE-2020-28918

CVE-2020-28918

Description

DualShield 5.9.8.0821 allows username enumeration on its login form. A valid username results in prompting for the password, whereas an invalid one will produce an "unknown username" error message.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DualShield 5.9.8.0821 login form reveals whether a username exists, enabling username enumeration.

Vulnerability

DualShield version 5.9.8.0821 contains a username enumeration vulnerability in its login form. The application returns different error messages depending on whether the submitted username exists: a valid username prompts for a password, while an invalid one returns an "unknown username" error. This behavior allows an attacker to determine valid usernames. [3]

Exploitation

An attacker with network access to the DualShield login page can send repeated login requests with different usernames and observe the response. No authentication or special privileges are required. The attacker can systematically test usernames to identify which ones are registered. [3]

Impact

Successful exploitation enables an attacker to enumerate valid usernames. This information can be used to target specific accounts in subsequent attacks, such as password guessing or social engineering. The CVSS v3.1 score is 5.4 (medium), with low confidentiality impact and no impact on integrity or availability. [3]

Mitigation

The vulnerability is fixed in DualShield version 6.0. Administrators must enable the new "Prevent login name guessing" checkbox in the authentication panel to prevent enumeration. Users should upgrade to version 6.0 or later. [3]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.