CVE-2020-6760
CRITICALSchmid ZI 620 V400 VPN 090 - OS Command Injection via SSH Subcommand Menu
Title source: llmDescription
Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/0xedh/someshit/blob/master/CVE-2020-6760.md
Scores
CVSS v3
9.8
EPSS
0.0171
EPSS Percentile
74.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (1)
schmid-telecom/zi_620_v400_firmware
090
Published
Feb 06, 2020
Tracked Since
Feb 18, 2026