VYPR

Platinum 4410 Firmware

by Genexis

CVEs (7)

  • CVE-2021-29003CriApr 13, 2021
    risk 0.70cvss 9.8epss 0.45

    Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI.

  • CVE-2020-6170CriJan 8, 2020
    risk 0.67cvss 9.8epss 0.07

    An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.

  • CVE-2025-65883HigDec 4, 2025
    risk 0.55cvss 8.4epss 0.00

    A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to improper session invalidation after administrator logout.…

  • CVE-2020-25988MedNov 17, 2020
    risk 0.45cvss 6.5epss 0.03

    UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the attacker is network adjacent.

  • CVE-2020-25015MedSep 16, 2020
    risk 0.45cvss 6.5epss 0.03

    A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s…

  • CVE-2020-28137MedNov 10, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router.

  • CVE-2020-27980MedOct 28, 2020
    risk 0.35cvss 5.4epss 0.01

    Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users.