CVE-2020-9436: OS Command Injection
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated users to inject system commands through a modified POST request to a specific URL.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-9436.
What is the severity of CVE-2020-9436?
The severity of CVE-2020-9436 is critical with a CVSS score of 8.8.
Which devices are affected by CVE-2020-9436?
The affected devices include PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17.
How can the vulnerability be exploited?
Authenticated users can exploit the vulnerability to inject system commands.
Are there any fixes available for CVE-2020-9436?
It is recommended to apply the latest firmware updates provided by PHOENIX CONTACT to mitigate the vulnerability.