First published: Mon Dec 14 2020(Updated: )
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
NEC Aterm SA3500G Firmware | <3.5.9 | |
NEC Aterm SA3500G Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5635 is rated as high severity due to the risk of arbitrary command execution.
To fix CVE-2020-5635, upgrade the Aterm SA3500G firmware to version 3.5.9 or later.
CVE-2020-5635 affects users of the NEC Aterm SA3500G firmware versions prior to 3.5.9.
An attacker can exploit CVE-2020-5635 to execute arbitrary commands on the device remotely.
There is no known workaround for CVE-2020-5635; the only mitigation is to upgrade the firmware.