CVE-2020-5635: OS Command Injection
Published Dec 14, 2020
·Updated
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.
Affected Software
2 affected components
Necplatforms Aterm Sa3500g Firmware<3.5.9
Necplatforms Aterm Sa3500g
Event History
Dec 14, 2020
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5635?
CVE-2020-5635 is rated as high severity due to the risk of arbitrary command execution.
2
How do I fix CVE-2020-5635?
To fix CVE-2020-5635, upgrade the Aterm SA3500G firmware to version 3.5.9 or later.
3
Who is affected by CVE-2020-5635?
CVE-2020-5635 affects users of the NEC Aterm SA3500G firmware versions prior to 3.5.9.
4
What types of attacks can be executed via CVE-2020-5635?
An attacker can exploit CVE-2020-5635 to execute arbitrary commands on the device remotely.
5
Is there a workaround for CVE-2020-5635?
There is no known workaround for CVE-2020-5635; the only mitigation is to upgrade the firmware.