CVE-2020-37135

HIGH

AMSS++ 4.7 - Authentication Bypass via Hardcoded Credentials

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37135. PoCs published by indoushka.

AI-analyzed exploit summary This exploit reveals a backdoor admin account in AMSS++ 4.7, allowing unauthorized access using the credentials 'admin' and '1234'. The PoC is trivial and relies on default credentials left in the software.

Description

AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.

Exploits (1)

exploitdb WORKING POC
by indoushka · textwebappsphp
https://www.exploit-db.com/exploits/48114

This exploit reveals a backdoor admin account in AMSS++ 4.7, allowing unauthorized access using the credentials 'admin' and '1234'. The PoC is trivial and relies on default credentials left in the software.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: AMSS++ 4.7
No auth needed
Prerequisites: Access to the login page of AMSS++ 4.7
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/48114
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/amss-backdoor-admin-account

Scores

CVSS v3 7.5
EPSS 0.0043
EPSS Percentile 34.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
Amssplus/AMSS++ 4.7
Published Feb 07, 2026
Tracked Since Feb 18, 2026