CVE-2020-8809

HIGH

Gurux GXDLMS Director <8.5.1905.1301 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-8809. PoCs published by seqred-s-a.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2020-8809, a vulnerability in Gurux GXDLMS Director involving insecure download mechanisms and path traversal, leading to remote code execution. It includes reproduction steps and mitigation advice.

Description

Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by modifying the contents of gurux.fi/obis/files.xml and gurux.fi/updates/updates.xml. Then, the attacker can modify the contents of downloaded files. In the case of add-ins (if the user is using those), this will lead to code execution. In case of OBIS codes (which the user is always using as they are needed to communicate with the energy meters), this can lead to code execution when combined with CVE-2020-8810.

Exploits (1)

nomisec WRITEUP 1 stars
by seqred-s-a · poc
https://github.com/seqred-s-a/gxdlmsdirector-cve

This repository provides a detailed technical analysis of CVE-2020-8809, a vulnerability in Gurux GXDLMS Director involving insecure download mechanisms and path traversal, leading to remote code execution. It includes reproduction steps and mitigation advice.

Classification
Writeup 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Gurux GXDLMS Director (all versions prior to 8.5.1905.1301)
No auth needed
Prerequisites: Man-in-the-middle position · User interaction to accept update
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://seqred.pl/en/cve-gurux-gxdlms-director/
Exploit, Third Party Advisory x_refsource_misc
https://github.com/seqred-s-a/gxdlmsdirector-cve

Scores

CVSS v3 8.1
EPSS 0.0103
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-494
Status published
Products (1)
gurux/device_language_message_specification_director < 8.5.1905.1301
Published Feb 25, 2020
Tracked Since Feb 18, 2026