peter bassill · operator
$ cve CVE-2020-8171 JSON

CVE-2020-8171

9.8
CRITICAL · CVSS 3.1 · EPSS 3.9% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end-points containing functionalities that are vulnerable to command injection. It is possible to craft an input string that passes the filter check but still contains commands, resulting in remote code execution.Mitigation:Update to the latest AirMax AirOS firmware version available at the AirMax download page.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.88% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2020-05-26
Last modified2026-06-17

Affected (40)

VendorProduct
uiag-hp-2g16
uiag-hp-2g20
uiag-hp-5g23
uiag-hp-5g27
uiairgrid m
uiairgrid m2
uiairgrid m5
uiairos
uiar
uiar-hp
uibm2-ti
uibm2hp
uibm5-ti
uibm5hp
uiis-m5
uilbem5-23
uilitestation m5
uilocom2
uilocom5
uilocom9
uim2
uim3
uim365
uim5
uim900
uinb-2g18
uinb-5g22
uinb-5g25
uinbe-m2-13
uinbe-m5-16
uinbe-m5-19
uinbm3
uinbm365
uinbm9
uinsm2
uinsm3
uinsm365
uinsm5
uipbe-m2-400
uipbe-m5-300

References

→ the Explorer  ·  watch your stack  ·  NVD