Lucene search

K
cveMitreCVE-2020-8958
HistoryJul 15, 2020 - 9:15 p.m.

CVE-2020-8958

2020-07-1521:15:13
CWE-78
mitre
web.nvd.nist.gov
79
In Wild
5
cve-2020-8958
guangzhou
onu
v2801rw
v2804rgw
remote attackers
os commands
security vulnerability
nvd

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.688

Percentile

98.0%

Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the boaform/admin/formPing Dest IP Address field.

Affected configurations

Nvd
Node
gpononu1ge_router_wifi_onu_v2801rwMatch-
AND
gpononu1ge_router_wifi_onu_v2801rw_firmwareRange1.9.1-181203โ€“2.9.0-181024
Node
gpononu1ge\+3fe\+wifi_onu_v2804rgwMatch-
AND
gpononu1ge\+3fe\+wifi_onu_v2804rgw_firmwareRange1.9.1-181203โ€“2.9.0-181024
VendorProductVersionCPE
gpononu1ge_router_wifi_onu_v2801rw-cpe:2.3:h:gpononu:1ge_router_wifi_onu_v2801rw:-:*:*:*:*:*:*:*
gpononu1ge_router_wifi_onu_v2801rw_firmware*cpe:2.3:o:gpononu:1ge_router_wifi_onu_v2801rw_firmware:*:*:*:*:*:*:*:*
gpononu1ge\+3fe\+wifi_onu_v2804rgw-cpe:2.3:h:gpononu:1ge\+3fe\+wifi_onu_v2804rgw:-:*:*:*:*:*:*:*
gpononu1ge\+3fe\+wifi_onu_v2804rgw_firmware*cpe:2.3:o:gpononu:1ge\+3fe\+wifi_onu_v2804rgw_firmware:*:*:*:*:*:*:*:*

Social References

More

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.688

Percentile

98.0%