CVSS v3
9.8
CRITICAL
EPSS Score
84.9%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
Active exploitation of CVE-2020-16152 has not been confirmed. The EPSS score is 84.9%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2020-16152 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).