CVE-2020-12843 is a critical vulnerability affecting ismartgate PRO 1.5.9 and gogogate ismartgate_pro firmware, allowing unauthenticated attackers to upload malicious files by exploiting a flaw in the sound upload function, bypassing security checks with specific WAV magic bytes. With a CVSS score of 9.8, this vulnerability presents a low-complexity attack vector (AV:N/AC:L/PR:N/UI:N) that can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Despite its high severity and potential for remote exploitation, there is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with typical trends for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.9CPE matchmatch criteria | cpe:2.3:o:gogogate:ismartgate_pro_firmware:1.5.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.