CVE-2020-17456
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 74%
from disclosure to weapon155 days
Published on NVDAug 19
1st PoC+155d
VulnCheck+601d
exploitation probability
74%top 1% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.
Affected products
n/a · n/apublic PoCs found — 5
cve_referencewww.exploit-db.com/exploits/50821unverifiedgithubgithub.com/Al1ex/CVE-2020-17456★ 4cve_referencepacketstormsecurity.com/files/158933/Seowon-SlC-130-Router-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/166273/Seowon-SLR-120-Router-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/1f6ac6bc0f89unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/158933/Seowon-SlC-130-Router-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/166273/Seowon-SLR-120-Router-Remote-Code-Execution.htmlhttps://github.com/TAPESH-TEAM/CVE-2020-17456-Seowon-SLR-120S42G-RCE-Exploit-Unauthenticatedhttps://maj0rmil4d.github.io/Seowon-SlC-130-And-SLR-120S-Exploit/https://www.exploit-db.com/exploits/50821