First published: Mon Feb 17 2020(Updated: )
ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eltex-co Ntp-2 | =3.25.1.1226 | |
NTP | =1v5\-b\+10 | |
Eltex-co Ntp-rg-1402g | =3.25.3.32 | |
Eltex-co Ntp-rg-1402g Firmware | =1v10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9026 is classified as a high-severity vulnerability due to its potential for OS command injection.
To fix CVE-2020-9026, upgrade the firmware of affected devices to the latest version released by Eltex.
CVE-2020-9026 affects Eltex NTP-RG-1402G version 3.25.3.32 and NTP-2 firmware version 3.25.1.1226.
CVE-2020-9026 is an OS command injection vulnerability that allows unauthorized command execution.
As of the latest reports, there are indications that CVE-2020-9026 may be actively targeted by attackers.