Vulnerability in Aterm Series Routers by NEC Allows Remote Command Execution
CVE-2020-5524

8.8HIGH

Key Information:

Vendor
CVE Published:
21 February 2020

What is CVE-2020-5524?

Aterm series routers manufactured by NEC are exposed to a vulnerability that permits an attacker within the same network segment to execute arbitrary operating system commands with root privileges. This exploitation is made possible via the Universal Plug and Play (UPnP) functionality, highlighting the critical need for network security measures to mitigate such risks.

Affected Version(s)

Aterm series Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.