← Back to browse · API

CVE-2020-8657

Severity
CRITICAL
CVSS
9.8
EPSS
0.91874
Risk score
57.16
CISA KEV
Yes
PoC
No
Published
2020-02-06
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-29505, GHSA-3W5R-GMMJ-PRC2
Products
EyesOfNetwork:EyesOfNetwork, n/a:n/a n/a
Sources
cisa.gov CVE-2020-8657
euvd EUVD-2020-29505

Description

An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.

References