Record summary

CVE-2020-20601 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 5, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALThinkCMF X2.2.2 - Remote Code ExecutionCVSS 9.8

ThinkCMF X2.2.2 and below contain a remote code execution caused by processing crafted packets, letting attackers execute arbitrary code remotely, exploit requires sending malicious packets.

Impact

Unauthenticated attackers can execute arbitrary PHP code on ThinkCMF servers, leading to complete server compromise and access to all website data.

Remediation

Upgrade to ThinkCMF version X2.2.3 or later.

WeaknessesCWE-94
Authorspikpikcu
Template tagscvecve2020thinkcmfrcevulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:thinkcmf:thinkcmf:x2.2.2:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2