Arbitrary Command Execution in Aterm SA3500G Firmware by NEC Platforms
CVE-2020-5635
8.8HIGH
What is CVE-2020-5635?
The firmware of the Aterm SA3500G, prior to version 3.5.9, contains a vulnerability that allows an attacker on an adjacent network to exploit a specific URL. By sending a specially crafted request, an attacker can execute arbitrary commands on the device, potentially leading to unauthorized access or control.
Affected Version(s)
Aterm SA3500G firmware versions prior to Ver. 3.5.9