Vulnerability Description
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute arbitrary commands with root user privileges.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amino | Ak45X Firmware | - |
| Amino | Ak45X | - |
| Amino | Ak5Xx Firmware | - |
| Amino | Ak5Xx | - |
| Amino | Ak65X Firmware | - |
| Amino | Ak65X | - |
| Amino | Aria6Xx Firmware | - |
| Amino | Aria6Xx | - |
| Amino | Aria7Xx Firmware | - |
| Amino | Aria7Xx | - |
| Amino | Kami7B Firmware | - |
| Amino | Kami7B | - |
Related Weaknesses (CWE)
References
- https://andre-oudhof.medium.com/pwning-my-isps-stbs-c5e78544274d#9cf3ExploitThird Party Advisory
- https://andre-oudhof.medium.com/pwning-my-isps-stbs-c5e78544274d#9cf3ExploitThird Party Advisory
FAQ
What is CVE-2020-10208?
CVE-2020-10208 is a vulnerability with a CVSS score of 9.9 (CRITICAL). Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute ar...
How severe is CVE-2020-10208?
CVE-2020-10208 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-10208?
Check the references section above for vendor advisories and patch information. Affected products include: Amino Ak45X Firmware, Amino Ak45X, Amino Ak5Xx Firmware, Amino Ak5Xx, Amino Ak65X Firmware.