CVE-2020-17456 describes an unauthenticated Remote Code Execution (RCE) vulnerability in SEOWON INTECH SLC-130 and SLR-120S devices, specifically through the ipAddr parameter on the system_log.cgi page. This critical vulnerability (CVSS 9.8) allows an attacker to execute arbitrary code with full impact on confidentiality, integrity, and availability, requiring no user interaction or privileges. While not listed in CISA's KEV catalog, public exploit code exists via Nuclei templates and ExploitDB, and it has been linked to the EnemyBot DDoS botnet, indicating active exploitation. Community discussion and media coverage are notably high, underscoring its significance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:seowonintech:slc-130_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:seowonintech:slr-120s_firmware:-:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:seowonintech:slr-120s42g_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:seowonintech:slr-120d42g_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:seowonintech:slr-120t42g_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.