Skip to main content

CVE-2020-12124

Description

A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.

NVD
Severity: CRITICAL
CVE ID: CVE-2020-12124
CVSS Score: 9.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Refrence: NVDMITRE

Proof Of Concept

Nuclei Templates for CVE-2020-12124
db44k

An implementation of a proof-of-concept for CVE-2020-12124 (https://cve.mitre.org/cgi-bin/cvename.cgi?name\=CVE-2020-12124)

Refrence: GitHub

Scorpion-Security-Labs

An implementation of a proof-of-concept for CVE-2020-12124

Refrence: GitHub