CVE-2020-10173 describes multiple authenticated command injection vulnerabilities in Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices, specifically through the ping and traceroute diagnostic pages. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating a critical risk where an authenticated attacker can achieve full compromise (confidentiality, integrity, availability) with low attack complexity over the network. Exploit code is publicly available via ExploitDB, and there is evidence of active exploitation by malware like Mirai and BotenaGo, as highlighted by significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
de11-416ssg-c01_r02.a2pvi042j1.d26mCPE matchmatch criteria | cpe:2.3:o:comtrend:vr-3033_firmware:de11-416ssg-c01_r02.a2pvi042j1.d26m:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.