peter bassill · operator
$ cve CVE-2020-10208 JSON

CVE-2020-10208

9.9
CRITICAL · CVSS 3.1 · EPSS 4.2% (pctl 91)

In your normal cycle

Critical by CVSS (9.9), but no sign of active exploitation.

Description

Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute arbitrary commands with root user privileges.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS4.17% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploitnone known
Published2020-12-30
Last modified2026-06-17

Affected (12)

VendorProduct
aminoak45x
aminoak45x firmware
aminoak5xx
aminoak5xx firmware
aminoak65x
aminoak65x firmware
aminoaria6xx
aminoaria6xx firmware
aminoaria7xx
aminoaria7xx firmware
aminokami7b
aminokami7b firmware

References

→ the Explorer  ·  watch your stack  ·  NVD