CVE-2020-12837

HIGH

is smart gate PRO 1.5.9 - Code Injection

Title source: llm
STIX 2.1

Description

ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used.

References (2)

Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://ismartgate.com/secure-garage-door/
Exploit, Third Party Advisory x_refsource_misc
https://kth.diva-portal.org/smash/get/diva2:1464458/FULLTEXT01.pdf

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 57.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-434
Status published
Products (1)
gogogate/ismartgate_pro_firmware 1.5.9
Published Sep 24, 2020
Tracked Since Feb 18, 2026