CVE-2020-23160

HIGH

Pyrescom Termod4 <10.04k - RCE

Title source: llm
STIX 2.1

Description

Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.

Exploits (1)

nomisec WORKING POC
by Outpost24 · poc
https://github.com/Outpost24/Pyrescom-Termod-PoC

References (3)

Core 3
Core References
Product, Vendor Advisory x_refsource_misc
https://pyres.com/en/solutions/termod-4/
Exploit, Third Party Advisory x_refsource_misc
https://github.com/Outpost24/Pyrescom-Termod-PoC
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://outpost24.com/blog/multiple-vulnerabilities-discovered-in-Pyrescom-Termod4-smart-device

Scores

CVSS v3 8.8
EPSS 0.2087
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
pyres/termod4_firmware < 10.04k
Published Jan 26, 2021
Tracked Since Feb 18, 2026