CVE-2020-26525
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 25%
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.
Affected products
n/a · n/a