CVE-2020-10580

HIGH

Invigo ADM <5.0 - Command Injection

Title source: llm
STIX 2.1

Description

A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://cwe.mitre.org/data/definitions/77.html

Scores

CVSS v3 8.8
EPSS 0.0391
EPSS Percentile 89.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
invigo/automatic_device_management < 5.0
Published Mar 25, 2021
Tracked Since Feb 18, 2026