CVE-2020-11698

CRITICAL

SpamTitan 7.07 - Remote Code Execution via SNMP Community Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-11698. PoCs published by Felipe Molina, Christophe De La Fuente, Felipe Molina, including Metasploit module exploits/freebsd/webapp/spamtitan_unauth_rce.

AI-analyzed exploit summary This exploit leverages unauthenticated command injection in SpamTitan's snmp-x.php to inject SNMP directives into snmpd.conf, enabling remote code execution via SNMP queries. It sets up a reverse shell using Perl.

Description

An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.

Exploits (2)

exploitdb WORKING POC
by Felipe Molina · pythonwebappsphp
https://www.exploit-db.com/exploits/48856

This exploit leverages unauthenticated command injection in SpamTitan's snmp-x.php to inject SNMP directives into snmpd.conf, enabling remote code execution via SNMP queries. It sets up a reverse shell using Perl.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SpamTitan Gateway 7.07 (and possibly earlier versions)
No auth needed
Prerequisites: Network access to the target's snmp-x.php endpoint · Python 3 with requests and pysnmp libraries
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Christophe De La Fuente, Felipe Molina · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/freebsd/webapp/spamtitan_unauth_rce.rb

This Metasploit module exploits an improper input sanitization vulnerability in SpamTitan Gateway versions 7.01, 7.02, 7.03, and 7.07 to inject SNMP configuration directives, leading to unauthenticated remote code execution as root.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: TitanHQ SpamTitan Gateway 7.01, 7.02, 7.03, 7.07
No auth needed
Prerequisites: Network access to the target's HTTP (port 80) and SNMP (port 161) services
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory x_refsource_misc
https://www.spamtitan.com/
Third Party Advisory x_refsource_misc
https://github.com/felmoltor
Third Party Advisory x_refsource_misc
https://twitter.com/felmoltor
Exploit, Third Party Advisory x_refsource_misc
https://sensepost.com/blog/2020/clash-of-the-spamtitan/
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/159470/SpamTitan-7.07-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/160809/SpamTitan-7.07-Command-Injection.html

Scores

CVSS v3 9.8
EPSS 0.7367
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
titanhq/spamtitan 7.07
Published Sep 17, 2020
Tracked Since Feb 18, 2026