CyberSec.Space Logo
Back to CVE Browser

CVE-2020-25010

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1790%
EPSS Percentile5.10th
PublishedDec 17, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a payload in the request parameters as an instruction to write a file.

Affected Platforms (CPE)

πŸ’»
Kyland

Kps2204 6 Port Managed Din Rail Programmable Serial Device Firmware

= r0002.p05

References & Advisories

Related Vulnerabilities