CVE-2020-5636: OS Command Injection
Published Dec 14, 2020
·Updated
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.
Affected Software
2 affected components
Necplatforms Aterm Sa3500g Firmware<3.5.9
Necplatforms Aterm Sa3500g
Event History
Dec 14, 2020
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5636?
CVE-2020-5636 is considered a high severity vulnerability due to the potential for arbitrary command execution.
2
How do I fix CVE-2020-5636?
To fix CVE-2020-5636, update the Aterm SA3500G firmware to version 3.5.9 or later.
3
Who is affected by CVE-2020-5636?
CVE-2020-5636 affects users of the NEC Aterm SA3500G firmware versions prior to 3.5.9.
4
What type of attack does CVE-2020-5636 allow?
CVE-2020-5636 allows an attacker with administrative privileges to execute arbitrary commands through a crafted request.
5
When was CVE-2020-5636 published?
CVE-2020-5636 was published on December 11, 2020.