evenroute.com
https://evenroute.com/ CVE-2020-11963
CRITICAL
evenroute iqrouter_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2020-11963 has a selected CVSS score of 9.8 (critical).
Description
IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 23, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
iqrouter_firmwareBrowse evenroute / iqrouter_firmware | VulnCheck | Version data not supplied | |
References
5evenroute.zendesk.com
https://evenroute.zendesk.com/hc/en-us/articles/216107838-How-do-I-configure-an-IQrouter- nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-11963 openwrt.org
https://openwrt.org/docs/guide-quick-start/walkthrough_login pastebin.com
https://pastebin.com/grSCSBSu