HIGH · 8.8

CVE-2020-8949

Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devices allows remote attackers to execute arbitrary OS...

Vulnerability Description

Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devices allows remote attackers to execute arbitrary OS commands via shell metacharacters in a ping operation, as demonstrated by the cgi-bin/webui/admin/tools/app_ping/diag_ping/; substring.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GocloudS2A Wl Firmware4.2.7.16471
GocloudS2A Wl-
GocloudS2A Firmware4.2.7.17278
GocloudS2A-
GocloudS3A K2P Mtk Firmware4.2.7.16528
GocloudS3A K2P Mtk-
GocloudS3A Firmware4.3.0.16572
GocloudS3A-
GocloudIsp3000 Firmware4.3.0.17190
GocloudIsp3000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8949?

CVE-2020-8949 is a vulnerability with a CVSS score of 8.8 (HIGH). Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devices allows remote attackers to execute arbitrary OS...

How severe is CVE-2020-8949?

CVE-2020-8949 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8949?

Check the references section above for vendor advisories and patch information. Affected products include: Gocloud S2A Wl Firmware, Gocloud S2A Wl, Gocloud S2A Firmware, Gocloud S2A, Gocloud S3A K2P Mtk Firmware.