CVE-2020-36907: Extreme Networks Aerohive HiveOS <=11.x 11.x Unauthenticated Remote Denial of Service

Published Jan 6, 2026
·
Updated

Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.

Affected Software

1 affected component
Extreme Networks Aerohive HiveOS<=11.x

Event History

Jan 6, 2026
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Oct 1, 57986
Event
via NVD·06:08 AM

Frequently Asked Questions

1

What is the severity of CVE-2020-36907?

CVE-2020-36907 has a severity rating that indicates it can lead to a denial of service, impacting the availability of the NetConfig UI.

2

How do I fix CVE-2020-36907?

To fix CVE-2020-36907, update to the latest version of Aerohive HiveOS that addresses this vulnerability.

3

Who is affected by CVE-2020-36907?

CVE-2020-36907 affects users of Extreme Networks Aerohive HiveOS versions up to 11.x.

4

What type of attacks can exploit CVE-2020-36907?

CVE-2020-36907 can be exploited by sending crafted HTTP requests to the action.php5 script, leading to service disruption.

5

Can CVE-2020-36907 be exploited remotely?

Yes, CVE-2020-36907 can be exploited remotely by unauthenticated attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203