PT-2020-11975 · Amino Communications · Amino Communications Aria6Xx Series+5

Published

2020-12-29

·

Updated

2021-07-21

·

CVE-2020-10209

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B (affected versions not specified)
Description The issue concerns a Command Injection in the CPE WAN Management Protocol (CWMP) registration, allowing man-in-the-middle attackers to execute arbitrary commands with root level privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10209

Affected Products

Amino Communications Ak45X Series
Amino Communications Ak5Xx Series
Amino Communications Ak65X Series
Amino Communications Aria6Xx Series
Amino Communications Aria7/Ak7Xx Series
Amino Communications Kami7B