peter bassill · operator
$ cve CVE-2020-10173 JSON

CVE-2020-10173 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 77.1% (pctl 100)

Patch early

A public exploit exists.

Description

Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS77.13% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2020-03-05
Last modified2026-06-17

Affected (2)

VendorProduct
comtrendvr-3033
comtrendvr-3033 firmware

Public exploits

SourceTitleDate
exploit-dbComtrend VR-3033 - Command Injection2020-02-27

References

→ the Explorer  ·  watch your stack  ·  NVD