CVE-2020-37002
CRITICALAjenti 2.1.36 - Command Injection
Title source: llmDescription
Ajenti 2.1.36 contains an authentication bypass vulnerability that allows remote attackers to execute arbitrary commands after successful login. Attackers can leverage the /api/terminal/create endpoint to send a netcat reverse shell payload targeting a specified IP and port.
Exploits (1)
exploitdb
WORKING POC
by Ahmet Ümit BAYRAM · pythonwebappspython
https://www.exploit-db.com/exploits/48929
Scores
CVSS v3
9.8
EPSS
0.0055
EPSS Percentile
68.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (1)
Ajenti Project/Ajenti
2.1.36
Published
Jan 29, 2026
Tracked Since
Feb 18, 2026