CVE Feed

    Dashboard / CVE / CVE-2020-8171

    CVE-2020-8171

    We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end-points containing functionalities that are vulnerable to command injection. It is possible to craft an input string that passes the filter check but still contains commands, resulting in remote code execution.Mitigation:Update to the latest AirMax AirOS firmware version available at the AirMax download page.

    Published:May 26, 2020
    Last Modified:Nov 21, 2024
    EPS:May 26, 2020
    EPSS Score:0.06929
    CVSS Score:9.8

    Affected Products

    Vendor
    Ui
    Product
    Ag-hp-2g16
    Vendor
    Ui
    Product
    Ag-hp-2g20
    Vendor
    Ui
    Product
    Ag-hp-5g23
    Vendor
    Ui
    Product
    Ag-hp-5g27
    Vendor
    Ui
    Product
    Airgrid M
    Vendor
    Ui
    Product
    Airgrid M2
    Vendor
    Ui
    Product
    Airgrid M5
    Vendor
    Ui
    Product
    Airos
    Vendor
    Ui
    Product
    Ar
    Vendor
    Ui
    Product
    Ar-hp
    Vendor
    Ui
    Product
    Bm2-ti
    Vendor
    Ui
    Product
    Bm2hp
    Vendor
    Ui
    Product
    Bm5-ti
    Vendor
    Ui
    Product
    Bm5hp
    Vendor
    Ui
    Product
    Is-m5
    Vendor
    Ui
    Product
    Lbem5-23
    Vendor
    Ui
    Product
    Litestation M5
    Vendor
    Ui
    Product
    Locom2
    Vendor
    Ui
    Product
    Locom5
    Vendor
    Ui
    Product
    Locom9
    Vendor
    Ui
    Product
    M2
    Vendor
    Ui
    Product
    M3
    Vendor
    Ui
    Product
    M365
    Vendor
    Ui
    Product
    M5
    Vendor
    Ui
    Product
    M900
    Vendor
    Ui
    Product
    Nb-2g18
    Vendor
    Ui
    Product
    Nb-5g22
    Vendor
    Ui
    Product
    Nb-5g25
    Vendor
    Ui
    Product
    Nbe-m2-13
    Vendor
    Ui
    Product
    Nbe-m5-16
    Vendor
    Ui
    Product
    Nbe-m5-19
    Vendor
    Ui
    Product
    Nbm3
    Vendor
    Ui
    Product
    Nbm365
    Vendor
    Ui
    Product
    Nbm9
    Vendor
    Ui
    Product
    Nsm2
    Vendor
    Ui
    Product
    Nsm3
    Vendor
    Ui
    Product
    Nsm365
    Vendor
    Ui
    Product
    Nsm5
    Vendor
    Ui
    Product
    Pbe-m2-400
    Vendor
    Ui
    Product
    Pbe-m5-300
    Vendor
    Ui
    Product
    Pbe-m5-300-iso
    Vendor
    Ui
    Product
    Pbe-m5-400
    Vendor
    Ui
    Product
    Pbe-m5-400-iso
    Vendor
    Ui
    Product
    Pbe-m5-620
    Vendor
    Ui
    Product
    Pbm10
    Vendor
    Ui
    Product
    Pbm365
    Vendor
    Ui
    Product
    Pbm5
    Vendor
    Ui
    Product
    Picom2hp
    Vendor
    Ui
    Product
    Power Ap N
    Vendor
    Ui
    Product
    Rm2-ti
    Vendor
    Ui
    Product
    Rm5-ti

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High