← Back to browse · API

CVE-2020-23584

Severity
CRITICAL
CVSS
9.8
EPSS
0.41443
Risk score
53.71
CISA KEV
No
PoC
No
Published
2022-11-23
Modified
2025-04-25
First seen
2026-08-07
Aliases
EUVD-2020-16328, GHSA-Q533-3FW5-RQXJ
Products
n/a:n/a n/a
Sources
euvd EUVD-2020-16328

Description

Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.

References