Record summary

CVE-2020-29390 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 8, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALZeroshell 3.9.3 - Command InjectionCVSS 9.8

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

Impact

Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.

Remediation

Upgrade to the latest version of Zeroshell or apply security patches provided by the vendor.

WeaknessesCWE-78
AuthorsDhiyaneshDk
Template tagscvecve2020zeroshellrceroutervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:zeroshell:zeroshell:3.9.3:*:*:*:*:*:*:*
Shodan: http.title:"zeroshell"
FOFA: title="zeroshell"
Google: intitle:"zeroshell"

Source: ProjectDiscovery

References

2