CVE-2020-10539 describes a critical authentication bypass vulnerability in Epikur versions prior to 20.1.1. The software contains a hardcoded "backdoor password" (3p1kursupport) that, when hashed with MD5, allows any attacker to gain unauthorized access to the system, bypassing legitimate user credentials. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the presence of a universal backdoor password makes this a severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.1.1CPE matchmatch criteria | cpe:2.3:a:epikur:epikur:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.