KEVIntel
9.8
CVSS
Critical

CVE-2020-7980

PUBLISHED

Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI....

PoC available Remote Low complexity No user interaction
Vendor
Intellian
Product
Aptus Web
Published
Jan 25, 2020
EPSS
93.4% · 100% pctl

Description

Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.

nuclei_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 10.0

AV:N/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Proof of concept available

Recorded 2020-01-28 23:27:20 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Jun 05, 2025

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Xh4H/Satellian-CVE-2020-7980

github · Created 2020-01-28 23:27:20 UTC · 73 stars

PoC script that shows RCE vulnerability over Intellian Satellite controller

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • Added to KEVIntel