CVE-2020-11963

CRITICAL EXPLOITED

IQrouter Firmware < 3.3.1 - Unauthenticated Remote Code Execution via Bash Shell Metacharacter Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-11963 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”

References (4)

Core 4
Core References
Product x_refsource_misc
https://evenroute.com/
Third Party Advisory x_refsource_misc
https://pastebin.com/grSCSBSu

Scores

CVSS v3 9.8
EPSS 0.0315
EPSS Percentile 86.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2026-01-23
CWE
CWE-78
Status published
Products (1)
evenroute/iqrouter_firmware < 3.3.1
Published Apr 21, 2020
Tracked Since Feb 18, 2026