SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-8797

Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can authenticate as admin from the…

MEDIUM 6.7EPSS 0.93%

Does this matter?

Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.

Description

Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can authenticate as admin from the local network.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.93% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
juplink/rx4-1500 firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.