CVE-2020-11920

CRITICAL

Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14 - OS Command Injection via NFS Settings HOST/IP Field

Title source: llm
STIX 2.1

Description

An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS settings menu in the webserver running on the device. By injecting Bash commands via shell metacharacters here, the device executes arbitrary code with root privileges (all of the device's services are running as root).

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0419
EPSS Percentile 89.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
svakom/siime_eye_firmware 14.1.00000001.3.330.0.0.3.14
Published Feb 08, 2021
Tracked Since Feb 18, 2026