CVE-2020-10208
9.9
CRITICAL · CVSS 3.1 · EPSS 4.2% (pctl 91)
In your normal cycle
Critical by CVSS (9.9), but no sign of active exploitation.
Description
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute arbitrary commands with root user privileges.
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 4.17% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-12-30 |
| Last modified | 2026-06-17 |
Affected (12)
| Vendor | Product |
|---|---|
| amino | ak45x |
| amino | ak45x firmware |
| amino | ak5xx |
| amino | ak5xx firmware |
| amino | ak65x |
| amino | ak65x firmware |
| amino | aria6xx |
| amino | aria6xx firmware |
| amino | aria7xx |
| amino | aria7xx firmware |
| amino | kami7b |
| amino | kami7b firmware |
References
→ the Explorer · watch your stack · NVD