MEDIUM · 5.5

CVE-2020-24552

Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code ...

Vulnerability Description

Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code and execute system commands without privilege.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
AtoptechnologySe5901 Firmware>= 1.18, <= 1.40
AtoptechnologySe5901-
AtoptechnologySe5901B Firmware>= 1.18, <= 1.40
AtoptechnologySe5901B-
AtoptechnologySe5904D Firmware>= 1.18, <= 1.40
AtoptechnologySe5904D-
AtoptechnologySe5908 Firmware>= 1.18, <= 1.40
AtoptechnologySe5908-
AtoptechnologySe5908A Firmware>= 1.18, <= 1.40
AtoptechnologySe5908A-
AtoptechnologySe5916 Firmware>= 1.18, <= 1.40
AtoptechnologySe5916-
AtoptechnologySe5916A Firmware>= 1.18, <= 1.40
AtoptechnologySe5916A-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-24552?

CVE-2020-24552 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code ...

How severe is CVE-2020-24552?

CVE-2020-24552 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-24552?

Check the references section above for vendor advisories and patch information. Affected products include: Atoptechnology Se5901 Firmware, Atoptechnology Se5901, Atoptechnology Se5901B Firmware, Atoptechnology Se5901B, Atoptechnology Se5904D Firmware.