CVE-2020-6760

CRITICAL

Schmid ZI 620 V400 VPN 090 - OS Command Injection via SSH Subcommand Menu

Title source: llm
STIX 2.1

Description

Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0171
EPSS Percentile 74.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
schmid-telecom/zi_620_v400_firmware 090
Published Feb 06, 2020
Tracked Since Feb 18, 2026