CVE-2020-8949

HIGHCVSS 8.8/10EPSS 2.83%

Last modified

CVE-2020-8949 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devices allows remote attackers to execute arbitrary OS commands via shell metacharacters in a ping operation, as demonstrated by the cgi-bin/webui/admin/tools/app_ping/diag_ping/; substring.. EPSS estimates a 2.83% chance of exploitation in the next 30 days.

Description

Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devices allows remote attackers to execute arbitrary OS commands via shell metacharacters in a ping operation, as demonstrated by the cgi-bin/webui/admin/tools/app_ping/diag_ping/; substring.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.83%

84.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GocloudS2a Wl Firmware4.2.7.16471
GocloudS2a Firmware4.2.7.17278
GocloudS2a Firmware4.3.0.15815
GocloudS2a Firmware4.3.0.17193
GocloudS3a K2p Mtk Firmware4.2.7.16528
GocloudS3a Firmware4.3.0.16572
GocloudIsp3000 Firmware4.3.0.17190

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-8949?
Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devices allows remote attackers to execute arbitrary OS commands via shell metacharacters in a ping operation, as demonstrated by the cgi-bin/webui/admin/tools/app_ping/diag_ping/; substring.
How severe is CVE-2020-8949?
CVE-2020-8949 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 2.83% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8949?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8949?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST