CVE-2020-7244

HIGH

Comtech Stampede FX-1010 Firmware 7.4.3 - Authenticated Remote Code Execution via Poll Routes Router IP Address Field

Title source: llm
STIX 2.1

Description

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes page and entering shell metacharacters in the Router IP Address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0424
EPSS Percentile 89.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
comtech/stampede_fx-1010_firmware 7.4.3
Published Jan 20, 2020
Tracked Since Feb 18, 2026