OS Command Injection Vulnerability in Aterm Series Routers by NEC
CVE-2020-5525

8HIGH

Key Information:

Vendor
CVE Published:
21 February 2020

What is CVE-2020-5525?

The vulnerability found in the NEC Aterm series of routers allows an authenticated attacker on the same local network segment to execute arbitrary OS commands with root privileges via the device's management interface. Specifically, this affects the Aterm WF1200C, Aterm WG1200CR, and Aterm WG2600HS when operating on specified firmware versions. Admins should ensure prompt updates or configurations to mitigate potential exploitations.

Affected Version(s)

Aterm series Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.