PT-2020-11974 · Amino Communications+1 · Amino Communications Kami7B+6

Published

2020-12-29

·

Updated

2021-07-21

·

CVE-2020-10208

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series, Kami7B (affected versions not specified)
Description The issue allows authenticated remote attackers to execute arbitrary commands with root user privileges due to Command Injection in EntoneWebEngine.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10208

Affected Products

Amino Communications Ak45X Series
Amino Communications Ak5Xx Series
Amino Communications Ak65X Series
Amino Communications Aria6Xx Series
Amino Communications Aria7/Ak7Xx Series
Amino Communications Kami7B
Entonewebengine