Remote Command Execution Vulnerability in Aterm WG2600HS Firmware by NEC
CVE-2020-5534

8HIGH

Key Information:

Vendor
CVE Published:
21 February 2020

What is CVE-2020-5534?

The Aterm WG2600HS firmware versions 1.3.2 and earlier have a vulnerability that permits an authenticated attacker on the same network segment to execute arbitrary operating system commands with root privileges. This flaw occurs due to unspecified vectors, potentially exposing the device and network to unauthorized access and control. It is crucial for users to ensure they are running the latest firmware and to implement robust security practices to mitigate risks associated with this vulnerability.

Affected Version(s)

Aterm WG2600HS firmware Ver1.3.2 and earlier

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.