SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-24552

Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability.

HIGH 7.2EPSS 1.37%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code and execute system commands without privilege.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.37% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
atoptechnology/se5901 firmware · atoptechnology/se5901b firmware · atoptechnology/se5904d firmware · atoptechnology/se5908 firmware · atoptechnology/se5908a firmware · atoptechnology/se5916 firmware · atoptechnology/se5916a firmware
Source
twcert@cert.org.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.