HIGH · 8.8

CVE-2020-28695

Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code executi...

Vulnerability Description

Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code execution as root.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AskeyRtf3505Vw-N1 Br Sv G000 R3505Vwn1001 S32 7 Firmware-
AskeyRtf3505Vw-N1 Br Sv G000 R3505Vwn1001 S32 7-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-28695?

CVE-2020-28695 is a vulnerability with a CVSS score of 8.8 (HIGH). Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code executi...

How severe is CVE-2020-28695?

CVE-2020-28695 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-28695?

Check the references section above for vendor advisories and patch information. Affected products include: Askey Rtf3505Vw-N1 Br Sv G000 R3505Vwn1001 S32 7 Firmware, Askey Rtf3505Vw-N1 Br Sv G000 R3505Vwn1001 S32 7.