CVE-2020-8976

Publication date

2022-10-17 21:18:06

Family

INCIBE

State

PUBLISHED

Description

The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen, the victim user has to have an active session and triggers the malicious request.