KEVIntel
9.8
CVSS
Critical

CVE-2020-13167

PUBLISHED

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Netsweeper
Product
Netsweeper
Published
May 19, 2020
EPSS

Description

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.

nuclei_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2025-06-25 00:00:00 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Jun 25, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

netsweeper_webadmin_unixlogin

metasploit · Created Unknown

Metasploit module for CVE-2020-13167

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Detected by Metasploit

  • Added to KEVIntel