CVE-2020-37153
9.8
CRITICAL · CVSS 3.1 · EPSS 4.7% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.7% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2026-02-11 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| inextrix | astpp |
References
→ the Explorer · watch your stack · NVD