CVE-2020-8958

Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to...

Basic Information

CVE State
PUBLISHED
Reserved Date
February 12, 2020
Published Date
July 15, 2020
Last Updated
August 04, 2024
Vendor
n/a
Product
n/a
Description
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the boaform/admin/formPing Dest IP Address field.

CVSS Scores

CVSS v3.1

7.2 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

9.0

Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Exploit Status

Proof of Concept Available
Yes (added 2020-07-15 08:10:01 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-10-29 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

Asjidkalam/CVE-2020-8958

Type: github • Created: 2021-04-27 15:51:08 UTC • Stars: 5

CVE-2020-8958: Authenticated RCE exploit for NetLink HG323

qurbat/CVE-2020-8958

Type: github • Created: 2020-07-15 08:10:01 UTC • Stars: 7

Proof of concept for arbitrary OS command execution on Guangzhou/V-SOL 1GE ONU devices (CVE-2020-8958)

Timeline

  • CVE ID Reserved

  • Proof of Concept Exploit Available

  • CVE Published to Public

  • Added to KEVIntel