CRITICAL🇵🇱 Wersja polska

CVE-2020-16152

CVSS 9.8v3.1pub. 2021-11-14upd. 2024-11-21

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Extremenetworks Aerohive Netconfig

    HW
    Extremenetworks
    10.0r8a< 10.0r8a
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-38292CRITICAL9.8PL ✓same vendor

Path traversal w Extreme Networks XIQ-SE umożliwiający privilege escalation

CVE-2023-43119CRITICAL9.8PL ✓same vendor

Extreme Networks EXOS — privilege escalation przez Redis i Telnet

CVE-2023-35803CRITICAL9.8PL ✓same vendor

Buffer overflow w IQ Engine na urządzeniach Extreme Networks AP

CVE-2023-35802CRITICAL9.8PL ✓same vendor

Buffer overflow w protokole CAPWAP urządzeń Extreme Networks AP — RCE

CVE-2025-11192HIGH8.4same vendor

A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is ...