CVE-2020-17505

High PUBLISHED

Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands...

Vendor: Artica Product: Artica Web Proxy

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.8 High EPSS 82.2%

At a Glance

Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.

nuclei_scanner
CVE Published
Aug 12, 2020
Exploitation Reported
Oct 01, 2025
CVSS
8.8 High
EPSS
82.2%
Remote Low complexity No user interaction

CVE References