← back
CVE-2020-13167observed exploitation

CVE-2020-13167

62Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 95%
from disclosure to weapon0 days
Published on NVDMay 19
metasploitApr 28
VulnCheck+1301d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesVulnCheck
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.
Affected products
n/a · n/a